CVE-2024-34067Cross-site Scripting in Panel

Severity
6.1MEDIUMNVD
EPSS
0.5%
top 32.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 3

Description

Pterodactyl is a free, open-source game server management panel built with PHP, React, and Go. Importing a malicious egg or gaining access to wings instance could lead to cross site scripting (XSS) on the panel, which could be used to gain an administrator account on the panel. Specifically, the following things are impacted: Egg Docker images and Egg variables: Name, Environment variable, Default value, Description, Validation rules. Additionally, certain fields would reflect malicious input, b

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages2 packages

NVDpterodactyl/panel< 1.11.6
Packagistpterodactyl/panel< 1.11.6

Patches

🔴Vulnerability Details

2
OSV
Pterodactyl panel's admin area vulnerable to Cross-site Scripting2024-05-03
GHSA
Pterodactyl panel's admin area vulnerable to Cross-site Scripting2024-05-03