PT-2021-18231 · Unknown · Discord Recon Server

Omar Badran

·

Published

2021-04-20

·

Updated

2024-01-12

·

CVE-2021-29461

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Discord Recon Server versions prior to 0.0.3
Description: A vulnerability in Discord Recon Server could be exploited to read internal files from the system and write files into the system, resulting in remote code execution. The issue has been fixed in version 0.0.3.
Recommendations: For versions prior to 0.0.3, update to version 0.0.3 to resolve the issue. As a temporary workaround, one may copy the code from assets/CommandInjection.py in the Discord Recon Server code repository and overwrite vulnerable code from one's own Discord Recon Server implementation with code that contains the patch.

Fix

Code Injection

Argument Injection

Weakness Enumeration

Related Identifiers

CVE-2021-29461
GHSA-3M9V-V33C-G83X

Affected Products

Discord Recon Server