CVE-2020-15140
Severity CVSS v4.0:
Pending analysis
Type:
CWE-74
Injection
Publication date:
21/08/2020
Last modified:
18/11/2021
Description
In Red Discord Bot before version 3.3.11, a RCE exploit has been discovered in the Trivia module: this exploit allows Discord users with specifically crafted usernames to inject code into the Trivia module's leaderboard command. By abusing this exploit, it's possible to perform destructive actions and/or access sensitive information. This critical exploit has been fixed on version 3.3.11.
Impact
Base Score 3.x
9.60
Severity 3.x
CRITICAL
Base Score 2.0
5.50
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:cogboard:red_discord_bot:*:*:*:*:*:*:*:* | 3.3.11 (excluding) |
To consult the complete list of CPE names with products and versions, see this page