Описание
Ree6 is a moderation bot. This vulnerability would allow other server owners to create configurations such as "Better-Audit-Logging" which contain a channel from another server as a target. This would mean you could send log messages to another Guild channel and bypass raid and webhook protections. A specifically crafted log message could allow spamming and mass advertisements. This issue has been patched in version 1.9.9. There are currently no known workarounds.
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.9.9 (исключая)
cpe:2.3:a:ree6:ree6:*:*:*:*:*:*:*:*
EPSS
Процентиль: 31%
0.00116
Низкий
5.5 Medium
CVSS3
5.4 Medium
CVSS3
Дефекты
CWE-863
EPSS
Процентиль: 31%
0.00116
Низкий
5.5 Medium
CVSS3
5.4 Medium
CVSS3
Дефекты
CWE-863