SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2024-21663

Discord-Recon is vulnerable to remote code execution.

HIGH 8.8EPSS 1.54%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.54%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Discord-Recon is a Discord bot created to automate bug bounty recon, automated scans and information gathering via a discord server. Discord-Recon is vulnerable to remote code execution. An attacker is able to execute shell commands in the server without having an admin role. This vulnerability has been fixed in version 0.0.8.

CVSS 3.1
8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
1.54% probability · 73th percentile
CISA KEV
Not listed
Weakness
CWE-20, CWE-77
Affected
demon1a/discord-recon
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.