PT-2020-14335 · Discord · Red Discord Bot
Jackenmen
·
Published
2020-10-27
·
Updated
2022-05-24
·
CVE-2020-15278
CVSS v3.1
7.7
High
| Vector | AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Red Discord Bot versions prior to 3.4.1
Description
The issue is an unauthorized privilege escalation exploit in the Mod module, allowing Discord users with high privilege levels within a guild to bypass hierarchy checks under specific conditions. This can lead to destructive actions within the guild. The exploit has been fixed in version 3.4.1. As a temporary workaround, unloading the Mod module or disabling the massban command can render the exploit inaccessible.
Recommendations
For versions prior to 3.4.1, update to version 3.4.1 to completely patch the issue.
As a temporary workaround, consider unloading the Mod module with
unload mod or disabling the massban command with command disable global massban to minimize the risk of exploitation.Fix
Incorrect Authorization
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Red Discord Bot