PT-2026-48716 · Quest Bot · Quest-Bot
CVE-2026-47177
·
Published
2026-06-11
·
Updated
2026-06-11
CVSS v4.0
5.7
Medium
| Vector | AV:N/AC:L/AT:P/PR:H/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Quest Bot versions prior to 1.0.4
Description
A user with permissions to configure bot settings can set the ticket transcript channel to a channel they have access to. When tickets are closed, the bot exports the complete ticket history to this channel, potentially exposing private messages to users who were not authorized to view the original ticket channel.
Recommendations
Update to version 1.0.4.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quest-Bot