Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The ProBot bot through 2021-02-08 for Discord might allow attackers to interfere with the intended purpose of the "Send an image when a user joins the server" feature (or possibly have unspecified other impact) because the uploader web service allows double extensions (such as .html.jpg) with the text/html content type. NOTE: there may not be cases in which an uploader web service is customer controlled; however, the nature of the issue has substantial interaction with customer controlled configuration. NOTE: the vendor states "This is just an uploader (like any other one) which uploads files to cloud storage and accepts various file types. There is no kind of vulnerability and it won't compromise either the client side or the server side.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
ProBot bot 代码问题漏洞
Vulnerability Description
ProBot bot 2021-02-08 之前版本中存在代码问题漏洞,该漏洞源于服务器对上传图片要求为text/html格式,攻击者可通过该漏洞干扰用户上传图片的操作。
CVSS Information
N/A
Vulnerability Type
N/A