CVE-2022-39302 MEDIUM

CVE-2022-39302: Ree6 may bypass webhook protection

Vendor Ree6-Applications
Product Ree6
Weakness CWE-863 · Incorrect authorization
Published October 13, 2022
Last update April 23, 2025

CVSS base score

5.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L

What the vulnerability does

01Description

Ree6 is a moderation bot. This vulnerability would allow other server owners to create configurations such as "Better-Audit-Logging" which contain a channel from another server as a target. This would mean you could send log messages to another Guild channel and bypass raid and webhook protections. A specifically crafted log message could allow spamming and mass advertisements. This issue has been patched in version 1.9.9. There are currently no known workarounds.

Key dates

02Disclosure timeline

October 13, 2022 CVE published
April 23, 2025 Record updated