Back to overview

CVE-2024-21663

CRITICAL Exploitation: PoC
10.0
CVSS 3.1
Description
Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a discord server. Discord-Recon is vulnerable to remote code execution. An attacker is able to execute shell commands in the server without having an admin role. This vulnerability has been fixed in version 0.0.8.

Metadata

CVE ID
CVE-2024-21663
State
PUBLISHED
Assigner
GitHub_M
Reserved
2023-12-29 16:10 UTC
Published
2024-01-08 23:57 UTC
Last updated
2024-09-04 15:15 UTC
Primary CWE
CWE-20
CWE-20: Improper Input Validation
Vendor / Product
DEMON1A / Discord-Recon
Sources
cve.org  ·  NVD

Severity & Metrics

10.0 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
PoC
Automatable
no
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
DEMON1A Discord-Recon < 0.0.8
Weakness (CWE)
CWESourceDescription
CWE-20 cna CWE-20: Improper Input Validation
CVSS scores (1)
ScoreSeverityVersionSourceVector
10.0 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
References (3)
Back to overview