PT-2024-19005 · Unknown · Discord-Recon

Micro0X00

·

Published

2024-01-08

·

Updated

2024-01-12

·

CVE-2024-21663

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Discord-Recon versions prior to 0.0.8
Description Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans, and information gathering via a Discord server. It is vulnerable to remote code execution, allowing an attacker to execute shell commands in the server without having an admin role.
Recommendations For versions prior to 0.0.8, update to version 0.0.8 to resolve the issue. As a temporary workaround, consider restricting access to the Discord server or disabling the bot until the update can be applied.

Exploit

Fix

RCE

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-21663
GHSA-FJCJ-G7X8-4RP7

Affected Products

Discord-Recon