PT-2022-24885 · Ree6 · Ree6

Dxssucuk

·

Published

2022-10-13

·

Updated

2022-10-17

·

CVE-2022-39302

CVSS v3.1

5.5

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Ree6 versions prior to 1.9.9
Description This issue allows other server owners to create configurations that contain a channel from another server as a target, enabling the sending of log messages to another Guild channel and bypassing raid and webhook protections. A specifically crafted log message could allow spamming and mass advertisements.
Recommendations For versions prior to 1.9.9, update to version 1.9.9 to resolve the issue. As a temporary workaround, consider restricting the use of the "Better-Audit-Logging" configuration to minimize the risk of exploitation. Avoid using configurations that contain channels from other servers as targets until the issue is resolved.

Exploit

Fix

Incorrect Authorization

Weakness Enumeration

Related Identifiers

CVE-2022-39302
GHSA-V574-XGCF-5W8X

Affected Products

Ree6