漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Quest Bot: Per-channel permission overwrite bypass in purge and slowmode commands.
Vulnerability Description
Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the purge and slowmode commands check only guild-level permissions on the invoking member. They do not check the member’s effective permissions in the channel where the command is run. A user denied channel-level moderation permissions can still delete messages or change slowmode through the bot. This issue has been patched in version 1.1.6.
CVSS Information
N/A
Vulnerability Type
授权机制不正确
Vulnerability Title
duck-organization Quest Bot 授权问题漏洞
Vulnerability Description
Duck Organization Quest Bot是Duck Organization组织的一款云计算虚拟化软件。 duck-organization Quest Bot 1.1.6之前版本存在授权问题漏洞,该漏洞源于权限检查不足,未检查用户在频道中的有效权限,可能导致被拒绝频道级别管理权限的用户仍可通过机器人删除消息或修改慢速模式。
CVSS Information
N/A
Vulnerability Type
N/A