CVE-2024-26136
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Feb 20, 2024
Updated: Feb 22, 2024
CWE ID 200
Summary
CVE-2024-26136: A vulnerability was discovered in kedi ElectronCord, a Discord bot management tool. The issue involves an exposed account access token in the `config.json` file. Malicious actors could exploit this vulnerability to gain unauthorized access to sensitive information or perform malicious actions on the repository owner's behalf. The extent of the damage depends on the level of access associated with the token. It is currently unknown if the repository owner has taken steps to mitigate the risk, such as rotating the token.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share