PT-2020-14335 · Discord · Red Discord Bot

Jackenmen

·

Published

2020-10-27

·

Updated

2022-05-24

·

CVE-2020-15278

CVSS v3.1

7.7

High

VectorAV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Red Discord Bot versions prior to 3.4.1
Description The issue is an unauthorized privilege escalation exploit in the Mod module, allowing Discord users with high privilege levels within a guild to bypass hierarchy checks under specific conditions. This can lead to destructive actions within the guild. The exploit has been fixed in version 3.4.1. As a temporary workaround, unloading the Mod module or disabling the massban command can render the exploit inaccessible.
Recommendations For versions prior to 3.4.1, update to version 3.4.1 to completely patch the issue. As a temporary workaround, consider unloading the Mod module with unload mod or disabling the massban command with command disable global massban to minimize the risk of exploitation.

Fix

Incorrect Authorization

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15278
GHSA-MP9M-G7QJ-6VQR
GHSA-Q886-75M2-VFF8
PYSEC-2020-267

Affected Products

Red Discord Bot