What the vulnerability does
01Description
Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
What the vulnerability does
Unauthenticated Broken Authentication in miniOrange Discord Integration <= 2.2.4 versions.
Explanation of Vulnerability in Simple Terms
miniOrange Discord Integration versions up to 2.2.4 contain an authentication bypass vulnerability. An attacker can exploit this flaw to gain unauthorized access to the integration without valid credentials. The vulnerability requires specific network conditions but does not require user interaction. Affected sites should update immediately.
What an attacker can do
Bypass authentication and gain unauthorized access to the Discord integration without valid credentials.
Potential impact on your site
Attackers can access Discord integration features and potentially read or modify connected Discord data without authorization.
Conditions required to exploit
Network access to the vulnerable integration; no user interaction or authentication required.
Key dates
External resources
Related vulnerabilities