PT-2024-21294 · Unknown · Electroncord

Kedi

·

Published

2024-02-20

·

Updated

2025-02-05

·

CVE-2024-26136

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions ElectronCord (affected versions not specified)
Description ElectronCord is a bot management tool for Discord. A commit exposes an account access token in the config.json file. Malicious actors could potentially exploit this to gain unauthorized access to sensitive information or perform malicious actions on behalf of the repository owner. It is unknown whether the owner of the repository has rotated the token or taken other mitigation steps aside from informing users.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-26136
GHSA-PPWC-5VWP-MHW8

Affected Products

Electroncord