CVE-2024-34067
- EPSS 0.46%
- Veröffentlicht 03.05.2024 18:15:09
- Zuletzt bearbeitet 06.06.2025 19:15:40
Pterodactyl is a free, open-source game server management panel built with PHP, React, and Go. Importing a malicious egg or gaining access to wings instance could lead to cross site scripting (XSS) on the panel, which could be used to gain an adminis...
CVE-2021-41273
- EPSS 0.38%
- Veröffentlicht 17.11.2021 20:15:10
- Zuletzt bearbeitet 21.11.2024 06:25:56
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. Due to improperly configured CSRF protections on two routes, a malicious user could execute a CSRF-based attack against the following endpoints: Sending a tes...
CVE-2021-41176
- EPSS 0.52%
- Veröffentlicht 25.10.2021 17:15:09
- Zuletzt bearbeitet 21.11.2024 06:25:40
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. In affected versions of Pterodactyl a malicious user can trigger a user logout if a signed in user visits a malicious website that makes a request to the Pane...
CVE-2021-41129
- EPSS 1.75%
- Veröffentlicht 06.10.2021 20:15:19
- Zuletzt bearbeitet 21.11.2024 06:25:32
Pterodactyl is an open-source game server management panel built with PHP 7, React, and Go. A malicious user can modify the contents of a `confirmation_token` input during the two-factor authentication process to reference a cache value not associate...
CVE-2019-1020002
- EPSS 1.48%
- Veröffentlicht 29.07.2019 15:15:11
- Zuletzt bearbeitet 21.11.2024 04:18:10
Pterodactyl before 0.7.14 with 2FA allows credential sniffing.