pterodactyl/panel Security Advisories for v0.7.16 (5)
-
[MEDIUM] Pterodactyl Panel has plain-text logging of user passwords when two-factor authentication is disabled
PKSA-r7r5-9g2g-bhnx CVE-2024-49762 GHSA-c479-wq8g-57hr
Affected version: <1.11.8
Reported by:
GitHub -
[MEDIUM] Pterodactyl panel's admin area vulnerable to Cross-site Scripting
PKSA-w7w4-x3d5-y8hz CVE-2024-34067 GHSA-384w-wffr-x63q
Affected version: <1.11.6
Reported by:
GitHub -
[MEDIUM] Insufficient Session Expiration in Pterodactyl API
PKSA-2ydv-ypnd-xrp7 GHSA-7v3x-h7r2-34jv
Affected version: <1.7.0
Reported by:
GitHub -
[MEDIUM] Cross-Site Request Forgery allowing sending of test emails and generation of node auto-deployment keys
PKSA-yr2t-b9wk-qw33 CVE-2021-41273 GHSA-wwgq-9jhf-qgw6
Affected version: <1.6.6
Reported by:
GitHub -
[MEDIUM] XSS vulnerability when listing users on add & modify server pages.
PKSA-cmcr-x57y-1pq2 GHSA-5822-pw57-vv37
Affected version: >=1.0.0-rc.0,<=1.0.0-rc.6|<0.7.19
Reported by:
GitHub