Cog-Creators Red-Discordbot vulnerabilities
4 known vulnerabilities affecting cog-creators/red-discordbot.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2020-15140P3CRITICALCVSS 9.6fixed in 3.3.112020-08-21
CVE-2020-15140 [CRITICAL] CWE-74 CVE-2020-15140: In Red Discord Bot before version 3.3.11, a RCE exploit has been discovered in the Trivia module: th
In Red Discord Bot before version 3.3.11, a RCE exploit has been discovered in the Trivia module: this exploit allows Discord users with specifically crafted usernames to inject code into the Trivia module's leaderboard command. By abusing this exploit, it's possible to perform destructive actions and/or access sensitive information. This critical
ghsanvdosv
CVE-2020-15147P3HIGHCVSS 8.5fixed in 3.3.122020-08-21
CVE-2020-15147 [HIGH] CWE-94 CVE-2020-15147: Red Discord Bot before versions 3.3.12 and 3.4 has a Remote Code Execution vulnerability in the Stre
Red Discord Bot before versions 3.3.12 and 3.4 has a Remote Code Execution vulnerability in the Streams module. This exploit allows Discord users with specifically crafted "going live" messages to inject code into the Streams module's going live message. By abusing this exploit, it's possible to perform destructive actions and/or access sensitive infor
ghsanvdosv
CVE-2020-15278P3HIGHCVSS 7.5fixed in 3.4.12020-10-28
CVE-2020-15278 [HIGH] CWE-863 CVE-2020-15278: Red Discord Bot before version 3.4.1 has an unauthorized privilege escalation exploit in the Mod mod
Red Discord Bot before version 3.4.1 has an unauthorized privilege escalation exploit in the Mod module. This exploit allows Discord users with a high privilege level within the guild to bypass hierarchy checks when the application is in a specific condition that is beyond that user's control. By abusing this exploit, it is possible to perform destruc
ghsanvdosv
CVE-2024-39905P4MEDIUMCVSS 5.3v>= 3.5.0, < 3.5.102024-07-11
CVE-2024-39905 [MEDIUM] CWE-863 CVE-2024-39905: Red is a fully modular Discord bot. Due to a bug in Red's Core API, 3rd-party cogs using the `@comma
Red is a fully modular Discord bot. Due to a bug in Red's Core API, 3rd-party cogs using the `@commands.can_manage_channel()` command permission check without additional permission controls may authorize a user to run a command even when that user doesn't have permissions to manage a channel. None of the core commands or core cogs are affected. The
ghsanvdosv