
Cloud Vulnerability DB
A community-led vulnerabilities database
In Red Discord Bot versions 3.3.10 and earlier, a Remote Code Execution (RCE) vulnerability was discovered in the Trivia module, identified as CVE-2020-15140. The vulnerability was discovered and disclosed in August 2020, affecting the Trivia module's leaderboard command functionality. The vulnerability allowed Discord users with specifically crafted usernames to inject malicious code into the system (GitHub Advisory).
The vulnerability existed in the Trivia module's leaderboard command where user input from Discord usernames was not properly sanitized. The issue stemmed from an unnecessary .format call in the code that allowed for Python string formatting injection. This vulnerability was fixed in version 3.3.11 by removing the problematic format call (GitHub Commit).
The exploitation of this vulnerability could allow attackers to perform destructive actions and potentially access sensitive information through the injected code execution. The severity of this vulnerability was rated as High due to the potential for unauthorized code execution and system compromise (GitHub Advisory).
The vulnerability could be exploited by Discord users who could craft specific usernames that would trigger code injection when the Trivia module's leaderboard command was executed. The exploit was discovered and reported by security researcher douglascdev (GitHub Advisory).
The vulnerability was patched in Red Discord Bot version 3.3.11. As a temporary workaround, users of affected versions could unload the Trivia module using the command 'unload trivia' to prevent exploitation. However, updating to version 3.3.11 or later was strongly recommended for complete remediation (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."