Unrated severityNVD Advisory· Published Apr 20, 2021· Updated Aug 3, 2024
LFI and possible code execution on discord-recon using tools arguments
CVE-2021-29461
Description
Discord Recon Server is a bot that allows one to do one's reconnaissance process from one's Discord. A vulnerability in Discord Recon Server prior to 0.0.3 could be exploited to read internal files from the system and write files into the system resulting in remote code execution. This issue has been fixed in version 0.0.3. As a workaround, one may copy the code from assets/CommandInjection.py in the Discord Recon Server code repository and overwrite vulnerable code from one's own Discord Recon Server implementation with code that contains the patch.
Affected products
1- Range: < 0.0.3
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- github.com/DEMON1A/Discord-Recon/security/advisories/GHSA-3m9v-v33c-g83xmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.