Lucene search

K
cvelistGitHub_MCVELIST:CVE-2024-21663
HistoryJan 08, 2024 - 11:57 p.m.

CVE-2024-21663 Remote code execution on ReconServer due to improper input sanitization on the prips command

2024-01-0823:57:54
CWE-20
GitHub_M
www.cve.org
4
cve-2024-21663
remote code execution
discord-recon
improper input sanitization
reconserver
bug bounty
automation
information gathering
discord server
admin role
vulnerability fixed
version 0.0.8.

CVSS3

9.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

9.9

Confidence

High

EPSS

0.002

Percentile

55.1%

Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a discord server. Discord-Recon is vulnerable to remote code execution. An attacker is able to execute shell commands in the server without having an admin role. This vulnerability has been fixed in version 0.0.8.

CNA Affected

[
  {
    "vendor": "DEMON1A",
    "product": "Discord-Recon",
    "versions": [
      {
        "version": "< 0.0.8",
        "status": "affected"
      }
    ]
  }
]

CVSS3

9.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

AI Score

9.9

Confidence

High

EPSS

0.002

Percentile

55.1%

Related for CVELIST:CVE-2024-21663