CVE-2020-26249 describes a Remote Code Execution (RCE) vulnerability in the Red Discord Bot Dashboard, affecting versions prior to 0.1.7a. This flaw allows malicious Discord users to inject code into the webserver front-end by crafting special server names or usernames/nicknames. With a CVSS score of 8.7 (HIGH), the vulnerability has a network attack vector, low attack complexity, and requires user interaction, potentially leading to high impact on confidentiality and integrity. While no active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB) has been identified, and community discussion is minimal, immediate patching to version 0.1.7a is crucial as there are no workarounds.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.1.2CPE matchmatch criteria | cpe:2.3:a:cogboard:red-dashboard:0.1.2:alpha0:*:*:*:*:*:* | ||
0.1.3CPE matchmatch criteria | cpe:2.3:a:cogboard:red-dashboard:0.1.3:alpha0:*:*:*:*:*:* | ||
0.1.4CPE matchmatch criteria | cpe:2.3:a:cogboard:red-dashboard:0.1.4:alpha0:*:*:*:*:*:* | ||
0.1.5CPE matchmatch criteria | cpe:2.3:a:cogboard:red-dashboard:0.1.5:alpha0:*:*:*:*:*:* | ||
0.1.6CPE matchmatch criteria | cpe:2.3:a:cogboard:red-dashboard:0.1.6:alpha0:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.