{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-11T08:24:59.433","vulnerabilities":[{"cve":{"id":"CVE-2020-26249","sourceIdentifier":"security-advisories@github.com","published":"2020-12-09T00:15:13.157","lastModified":"2024-11-21T05:19:38.843","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Red Discord Bot Dashboard is an easy-to-use interactive web dashboard to control your Redbot. In Red Discord Bot before version 0.1.7a an RCE exploit has been discovered. This exploit allows Discord users with specially crafted Server names and Usernames/Nicknames to inject code into the webserver front-end code. By abusing this exploit, it's possible to perform destructive actions and/or access sensitive information. This high severity exploit has been fixed on version 0.1.7a. There are no workarounds, bot owners must upgrade their relevant packages (Dashboard module and Dashboard webserver) in order to patch this issue."},{"lang":"es","value":"Red Discord Bot Dashboard es un panel web interactivo fácil de usar para controlar tu Redbot. En Red Discord Bot versiones anteriores a 0.1.7a ha sido detectado una explotación de RCE. Esta explotación permite a usuarios de Discord con nombres de Server y Usernames/Nicknames especialmente diseñados, inyectar código en el código del front-end del servidor web. Al abusar de esta explotación, es posible llevar a cabo acciones destructivas y/o acceder a información confidencial. Esta explotación de alta severidad ha sido corregida en la versión 0.1.7a. No se presentan soluciones provisionales, los propietarios de los bots deben actualizar sus paquetes relevantes (módulo de Dashboard y servidor web de Dashboard) para poder parchear este problema"}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":7.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.3,"impactScore":5.8},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.3,"impactScore":5.8}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:N/I:P/A:N","baseScore":3.5,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":6.8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-79"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-79"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:cogboard:red-dashboard:0.1.2:alpha0:*:*:*:*:*:*","matchCriteriaId":"E8CF51B9-B3EA-4B38-94AB-AA36BAAD6296"},{"vulnerable":true,"criteria":"cpe:2.3:a:cogboard:red-dashboard:0.1.3:alpha0:*:*:*:*:*:*","matchCriteriaId":"3A6ABE0E-5718-463F-9188-AC2FD94ECD44"},{"vulnerable":true,"criteria":"cpe:2.3:a:cogboard:red-dashboard:0.1.4:alpha0:*:*:*:*:*:*","matchCriteriaId":"E264D5C4-F0A5-469E-89F9-AD456723703E"},{"vulnerable":true,"criteria":"cpe:2.3:a:cogboard:red-dashboard:0.1.5:alpha0:*:*:*:*:*:*","matchCriteriaId":"96A9C2E7-B629-4B61-83D9-6E627480E82B"},{"vulnerable":true,"criteria":"cpe:2.3:a:cogboard:red-dashboard:0.1.6:alpha0:*:*:*:*:*:*","matchCriteriaId":"BAA08A22-1BAE-432B-A85C-8E40BA6B2184"}]}]}],"references":[{"url":"https://github.com/Cog-Creators/Red-Dashboard/commit/99d88b840674674166ce005b784ae8e31e955ab1","source":"security-advisories@github.com","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/Cog-Creators/Red-Dashboard/commit/a6b9785338003ec87fb75305e7d1cc2d40c7ab91","source":"security-advisories@github.com","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/Cog-Creators/Red-Dashboard/security/advisories/GHSA-hm45-mgqm-gjm4","source":"security-advisories@github.com","tags":["Patch","Third Party Advisory"]},{"url":"https://pypi.org/project/Red-Dashboard","source":"security-advisories@github.com","tags":["Product","Third Party Advisory"]},{"url":"https://github.com/Cog-Creators/Red-Dashboard/commit/99d88b840674674166ce005b784ae8e31e955ab1","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/Cog-Creators/Red-Dashboard/commit/a6b9785338003ec87fb75305e7d1cc2d40c7ab91","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/Cog-Creators/Red-Dashboard/security/advisories/GHSA-hm45-mgqm-gjm4","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://pypi.org/project/Red-Dashboard","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Product","Third Party Advisory"]}]}}]}