Filtered by vendor Premid Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2020-24928 1 Premid 1 Premid 2024-08-04 5.3 Medium
managers/socketManager.ts in PreMiD through 2.1.3 has a locally hosted socketio web server (port 3020) open to all origins, which allows attackers to obtain sensitive Discord user information.
CVE-2021-46701 1 Premid 1 Premid 2024-08-04 7.2 High
PreMiD 2.2.0 allows unintended access via the websocket transport. An attacker can receive events from a socket and emit events to a socket, potentially interfering with a victim's "now playing" status on Discord.