CVE-2023-22452 affects the kenny2automate Discord bot, specifically its web interface for server settings. The vulnerability allowed an authenticated attacker to modify settings for any Discord channel by manipulating channel IDs in form submissions, regardless of which server was being configured. This medium-severity flaw (CVSS 6.5) has a low attack complexity and could lead to high integrity impact (unauthorized settings changes). The issue has been patched in commit a947d7c and deployed to the official bot instance; there is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< a947d7cCPE matchmatch criteria | cpe:2.3:a:kenny2automate_project:kenny2automate:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.