Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-29465

Опубликовано: 22 апр. 2021
Источник: nvd
CVSS3: 8.3
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

Discord-Recon is a bot for the Discord chat service. Versions of Discord-Recon 0.0.3 and prior contain a vulnerability in which a remote attacker is able to overwrite any file on the system with the command results. This can result in remote code execution when the user overwrite important files on the system. As a workaround, bot maintainers can edit their setting.py file then add < and > into the RCE variable inside of it to fix the issue without an update. The vulnerability is patched in version 0.0.4.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:discord:discord-recon:*:*:*:*:*:*:*:*
Версия до 0.0.4 (исключая)

EPSS

Процентиль: 88%
0.03684
Низкий

8.3 High

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-94
CWE-78

EPSS

Процентиль: 88%
0.03684
Низкий

8.3 High

CVSS3

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-94
CWE-78