PT-2022-24885 · Ree6 · Ree6
Dxssucuk
·
Published
2022-10-13
·
Updated
2022-10-17
·
CVE-2022-39302
CVSS v3.1
5.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Ree6 versions prior to 1.9.9
Description
This issue allows other server owners to create configurations that contain a channel from another server as a target, enabling the sending of log messages to another Guild channel and bypassing raid and webhook protections. A specifically crafted log message could allow spamming and mass advertisements.
Recommendations
For versions prior to 1.9.9, update to version 1.9.9 to resolve the issue. As a temporary workaround, consider restricting the use of the "Better-Audit-Logging" configuration to minimize the risk of exploitation. Avoid using configurations that contain channels from other servers as targets until the issue is resolved.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ree6