PT-2024-25678 · Unknown · Pterodactyl
Trixterthetux
·
Published
2024-05-03
·
Updated
2025-06-06
·
CVE-2024-34067
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Pterodactyl versions prior to 1.11.6
Description
Importing a malicious egg or gaining access to a wings instance could lead to cross-site scripting (XSS) on the panel, potentially allowing an attacker to gain an administrator account. The impacted components include Egg Docker images and Egg variables:
Name, Environment variable, Default value, Description, and Validation rules. This issue requires an administrator to perform specific actions and cannot be triggered by a normal panel user.Recommendations
For versions prior to 1.11.6, update to version 1.11.6 to resolve the issue. No workaround is available other than updating to the latest version of the panel. As a temporary measure, consider restricting access to Egg Docker images and Egg variables to minimize the risk of exploitation.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pterodactyl