CVE-2020-15140 - CVE House
Back to Database
Status published High CVE-2020-15140

Remote Code Execution in Red Discord Bot

Vulnerability Description

In Red Discord Bot before version 3.3.11, a RCE exploit has been discovered in the Trivia module: this exploit allows Discord users with specifically crafted usernames to inject code into the Trivia module's leaderboard command. By abusing this exploit, it's possible to perform destructive actions and/or access sensitive information. This critical exploit has been fixed on version 3.3.11.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-15140

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Cog-Creators

View all reports →

Affected Software

Red-DiscordBot
Vulnerable Versions:
< 3.3.11

Timeline

Official Publish: August 21st, 2020
Last Modified: August 4th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N

Weaknesses (CWE)