PT-2023-18508 · Unknown · Kenny2Automate

Kenny2Github

·

Published

2023-01-02

·

Updated

2023-01-09

·

CVE-2023-22452

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions kenny2automate versions prior to commit a947d7c
Description The issue concerns a Discord bot where form elements in the web interface for server settings were generated with Discord channel IDs as part of input names. No validation was performed to ensure that the channel IDs submitted actually belonged to the server being configured. This allowed anyone with access to the channel ID and the server settings panel to change settings for the requested channel, regardless of the server it belonged to.
Recommendations For versions prior to commit a947d7c, update to a version that includes commit a947d7c to resolve the issue. As a temporary workaround for those who run their own instance of the bot, consider disabling the web config entirely by changing it to run on localhost.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2023-22452
GHSA-73J8-XRCR-Q6J7

Affected Products

Kenny2Automate