Pterodactyl

Panel

12 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.06%
  • Veröffentlicht 19.02.2026 15:55:20
  • Zuletzt bearbeitet 20.02.2026 19:08:53

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.1, a missing authorization check in multiple controllers allows any user with access to a node secret token to fetch informatio...

  • EPSS 0.05%
  • Veröffentlicht 19.01.2026 19:17:53
  • Zuletzt bearbeitet 02.02.2026 20:41:13

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to version 1.12.0, websockets within wings lack proper rate limiting and throttling. As a result a malicious user can open a large number of co...

  • EPSS 0.05%
  • Veröffentlicht 19.01.2026 19:16:03
  • Zuletzt bearbeitet 02.02.2026 20:42:41

Pterodactyl is a free, open-source game server management panel. Pterodactyl implements rate limits that are applied to the total number of resources (e.g. databases, port allocations, or backups) that can exist for an individual server. These resour...

  • EPSS 0.01%
  • Veröffentlicht 06.01.2026 00:44:23
  • Zuletzt bearbeitet 12.01.2026 21:26:03

Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below allow TOTP to be used multiple times during its validity window. Users with 2FA enabled are prompted to enter a token during sign-in, and afterward it is not ...

  • EPSS 0.01%
  • Veröffentlicht 06.01.2026 00:31:14
  • Zuletzt bearbeitet 12.01.2026 21:29:12

Pterodactyl is a free, open-source game server management panel. Versions 1.11.11 and below do not revoke active SFTP connections when a user is removed from a server instance or has their permissions changes with respect to file access over SFTP. Th...

  • EPSS 12.18%
  • Veröffentlicht 20.06.2025 16:56:41
  • Zuletzt bearbeitet 23.06.2025 20:16:21

Pterodactyl is a free, open-source game server management panel. Prior to version 1.11.11, using the /locales/locale.json with the locale and namespace query parameters, a malicious actor is able to execute arbitrary code without being authenticated....

  • EPSS 0.03%
  • Veröffentlicht 24.10.2024 22:15:04
  • Zuletzt bearbeitet 25.10.2024 12:56:07

Pterodactyl is a free, open-source game server management panel. When a user disables two-factor authentication via the Panel, a `DELETE` request with their current password in a query parameter will be sent. While query parameters are encrypted whe...

  • EPSS 0.53%
  • Veröffentlicht 03.05.2024 18:15:09
  • Zuletzt bearbeitet 06.06.2025 19:15:40

Pterodactyl is a free, open-source game server management panel built with PHP, React, and Go. Importing a malicious egg or gaining access to wings instance could lead to cross site scripting (XSS) on the panel, which could be used to gain an adminis...

  • EPSS 0.12%
  • Veröffentlicht 17.11.2021 20:15:10
  • Zuletzt bearbeitet 21.11.2024 06:25:56

Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. Due to improperly configured CSRF protections on two routes, a malicious user could execute a CSRF-based attack against the following endpoints: Sending a tes...

  • EPSS 0.17%
  • Veröffentlicht 25.10.2021 17:15:09
  • Zuletzt bearbeitet 21.11.2024 06:25:40

Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. In affected versions of Pterodactyl a malicious user can trigger a user logout if a signed in user visits a malicious website that makes a request to the Pane...