PT-2020-14220 · Discord · Red Discord Bot

Douglascdev

·

Published

2020-08-21

·

Updated

2021-11-18

·

CVE-2020-15140

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Red Discord Bot versions prior to 3.3.11
Description A remote code execution exploit has been discovered in the Trivia module, allowing Discord users with specifically crafted usernames to inject code into the Trivia module's leaderboard command. This exploit can be used to perform destructive actions and/or access sensitive information.
Recommendations For versions prior to 3.3.11, update to version 3.3.11 to completely patch this issue. As a temporary workaround, consider unloading the Trivia module with unload trivia to render this exploit not accessible.

Fix

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15140
GHSA-55J9-849X-26H4
PYSEC-2020-265

Affected Products

Red Discord Bot