Headline
CVE-2018-25092: Release 2.10.3: fixed rulecode being visible · Vaerys-Dawn/DiscordSailv2
A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Command Mention Handler. The manipulation leads to improper access controls. Upgrading to version 2.10.3 is able to address this issue. The patch is named cc12e0be82a5d05d9f359ed8e56088f4f8b8eb69. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-244483.
- Releases
- 2.10.3
* Remove ability for CCs to contain existing command names.
* Make the return message more informative.
* Fixes a vulnerability in some commands that would allow users to use
mentions they would not normally have access to.
* fixed a bug involving the commands command showing dm commands
regardless of what page you were on.
+ added page system to the listJoinMessages
* fixed vulnerability in the tag handler that would allow users to use
mentions.
+ added ChannelSetting Profiles
* addprofile no longer adds profiles if the user already has one
+ added toggle SendJoinMessages
* renamed JoinServerMessages tp WelcomeMessages
fixed a bug that caused daily messages to crash
* stoped sail from logging pin messages
+ added Ban and kick logging
* Remove ability for CCs to contain existing command names.
* Make the return message more informative.
* Fixes a vulnerability in some commands that would allow users to use mentions they would not normally have access to.
+ Added subcommands to ModNote:
-> EditModNote
-> AddStrike/StrikeModNote
-> DeleteModNote/DelModnote
-> GetModNote
* fixed a bug that would allow users to see the Rulecode value in the
GetGuildInfo command output