CyberRota Analysis
AI-GeneratedLegcord versions 1.1.0 to 1.3.0 are vulnerable to a configuration injection flaw that permits attackers to manipulate configuration settings through a cross-site scripting (XSS) exploit on Discord. This vulnerability can lead to the persistent routing of client traffic through an interception proxy, compromising user privacy and security. Organizations utilizing Legcord should prioritize immediate remediation to mitigate the risk of traffic interception and potential data breaches.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Legcord 1.1.0 through 1.3.0 contains a configuration injection vulnerability that allows script in the Discord page to write any config key via the window.legcord settings.setConfig bridge. Attackers exploiting a Discord XSS can set additionalArguments to persistently add --proxy-server and --ignore-certificate-errors switches, routing all client traffic through an interception proxy.