Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-35237

Опубликовано: 27 мая 2024
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

MIT IdentiBot is an open-source Discord bot written in Node.js that verifies individuals' affiliations with MIT, grants them roles in a Discord server, and stores information about them in a database backend. A vulnerability that exists prior to commit 48e3e5e7ead6777fa75d57c7711c8e55b501c24e impacts all users who have performed verification with an instance of MIT IdentiBot that meets the following conditions: The instance of IdentiBot is tied to a "public" Discord application—i.e., users other than the API access registrant can add it to servers; and the instance has not yet been patched. In affected versions, IdentiBot does not check that a server is authorized before allowing members to execute slash and user commands in that server. As a result, any user can join IdentiBot to their server and then use commands (e.g., /kerbid) to reveal the full name and other information about a Discord user who has verified their affiliation with MIT using IdentiBot. The latest version of M

EPSS

Процентиль: 32%
0.00126
Низкий

7.5 High

CVSS3

Дефекты

CWE-862

EPSS

Процентиль: 32%
0.00126
Низкий

7.5 High

CVSS3

Дефекты

CWE-862