PT-2024-25678 · Unknown · Pterodactyl

Trixterthetux

·

Published

2024-05-03

·

Updated

2025-06-06

·

CVE-2024-34067

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Pterodactyl versions prior to 1.11.6
Description Importing a malicious egg or gaining access to a wings instance could lead to cross-site scripting (XSS) on the panel, potentially allowing an attacker to gain an administrator account. The impacted components include Egg Docker images and Egg variables: Name, Environment variable, Default value, Description, and Validation rules. This issue requires an administrator to perform specific actions and cannot be triggered by a normal panel user.
Recommendations For versions prior to 1.11.6, update to version 1.11.6 to resolve the issue. No workaround is available other than updating to the latest version of the panel. As a temporary measure, consider restricting access to Egg Docker images and Egg variables to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2024-34067
GHSA-384W-WFFR-X63Q

Affected Products

Pterodactyl