Lucene search

K
cve[email protected]CVE-2024-21663
HistoryJan 09, 2024 - 12:15 a.m.

CVE-2024-21663

2024-01-0900:15:44
CWE-20
CWE-77
web.nvd.nist.gov
19
discord-recon
bug bounty
recon
scanning
rce
automation
security

9.9 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

8.9 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.2%

Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a discord server. Discord-Recon is vulnerable to remote code execution. An attacker is able to execute shell commands in the server without having an admin role. This vulnerability has been fixed in version 0.0.8.

Affected configurations

Vulners
NVD
Node
demon1adiscord-reconRange<0.0.8
VendorProductVersionCPE
demon1adiscord\-recon*cpe:2.3:a:demon1a:discord\-recon:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "DEMON1A",
    "product": "Discord-Recon",
    "versions": [
      {
        "version": "< 0.0.8",
        "status": "affected"
      }
    ]
  }
]

9.9 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

8.9 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.2%

Related for CVE-2024-21663