CVE-2020-15140

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
21/08/2020
Last modified:
18/11/2021

Description

In Red Discord Bot before version 3.3.11, a RCE exploit has been discovered in the Trivia module: this exploit allows Discord users with specifically crafted usernames to inject code into the Trivia module's leaderboard command. By abusing this exploit, it's possible to perform destructive actions and/or access sensitive information. This critical exploit has been fixed on version 3.3.11.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cogboard:red_discord_bot:*:*:*:*:*:*:*:* 3.3.11 (excluding)