CVE-2020-15140
Summary
| CVE | CVE-2020-15140 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-21 17:15:00 UTC |
| Updated | 2021-11-18 18:36:00 UTC |
| Description | In Red Discord Bot before version 3.3.11, a RCE exploit has been discovered in the Trivia module: this exploit allows Discord users with specifically crafted usernames to inject code into the Trivia module's leaderboard command. By abusing this exploit, it's possible to perform destructive actions and/or access sensitive information. This critical exploit has been fixed on version 3.3.11. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [Trivia] Remove an unnecessary `.format` by Flame442 · Pull Request #4175 · Cog-Creators/Red-DiscordBot · GitHub |
MISC |
github.com |
Patch, Third Party Advisory |
| Remote Code Execution in Trivia module · Advisory · Cog-Creators/Red-DiscordBot · GitHub |
CONFIRM |
github.com |
Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 980041 Python (pip) Security Update for Red-DiscordBot (GHSA-55j9-849x-26h4)