Unrated severityNVD Advisory· Published Jan 8, 2024· Updated Sep 4, 2024
Remote code execution on ReconServer due to improper input sanitization on the prips command
CVE-2024-21663
Description
Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a discord server. Discord-Recon is vulnerable to remote code execution. An attacker is able to execute shell commands in the server without having an admin role. This vulnerability has been fixed in version 0.0.8.
Affected products
1- Range: < 0.0.8
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/DEMON1A/Discord-Recon/commit/f9cb0f67177f5e2f1022295ca8e641e47837ec7amitrex_refsource_MISC
- github.com/DEMON1A/Discord-Recon/issues/23mitrex_refsource_MISC
- github.com/DEMON1A/Discord-Recon/security/advisories/GHSA-fjcj-g7x8-4rp7mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.