First published: Mon Jan 08 2024(Updated: )
Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a discord server. Discord-Recon is vulnerable to remote code execution. An attacker is able to execute shell commands in the server without having an admin role. This vulnerability has been fixed in version 0.0.8.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Discord | <0.0.8 | |
Discord | =0.0.8-beta |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21663 has been classified as a high severity vulnerability due to its potential for remote code execution.
To address CVE-2024-21663, update Discord-Recon to the latest version, ensuring it is beyond 0.0.8.
CVE-2024-21663 allows an attacker to execute arbitrary shell commands on the Discord server, compromising its security.
CVE-2024-21663 affects Discord-Recon versions up to 0.0.8 and the 0.0.8-beta version.
Any Discord server using the vulnerable versions of Discord-Recon is at risk from CVE-2024-21663.