PT-2026-48862 · Quest Bot · Quest-Bot
CVE-2026-49347
·
Published
2026-06-12
·
Updated
2026-06-12
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Quest Bot versions prior to 1.1.8
Description
Users with access to the ticket panel can repeatedly create new ticket channels. The software creates a new database ticket and Discord channel for every completed ticket modal submission without verifying if the user already has an open ticket and without implementing a cooldown period.
Recommendations
Update to version 1.1.8.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Quest-Bot