Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a discord server. Discord-Recon is vulnerable to remote code execution. An attacker is able to execute shell commands in the server without having an admin role. This vulnerability has been fixed in version 0.0.8.
References
| Link | Resource |
|---|---|
| https://github.com/DEMON1A/Discord-Recon/security/advisories/GHSA-fjcj-g7x8-4rp7 | Exploit Patch Vendor Advisory |
| https://github.com/DEMON1A/Discord-Recon/issues/23 | Exploit Issue Tracking Third Party Advisory |
| https://github.com/DEMON1A/Discord-Recon/commit/f9cb0f67177f5e2f1022295ca8e641e47837ec7a | Patch |
Configurations
Configuration 1 (hide)
|
Information
Published : 2024-01-09 00:15
Updated : 2024-01-12 15:22
NVD link : CVE-2024-21663
Mitre link : CVE-2024-21663
JSON object : View
Products Affected
demon1a
- discord-recon
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
