Skip to content

XSS vulnerability when performing deletion and dropdown actions in filemanager.

High
DaneEveritt published GHSA-3q45-4vhr-c7g7 Jun 22, 2019 · 1 comment

Package

No package listed

Affected versions

< 0.7.13

Patched versions

0.7.14

Description

Impact

Affects all previous versions of Pterodactyl and is easily exploited in day-to-day activities.

Workarounds

No workaround to prevent this attack is available without manual code patching or updating to the latest version.

For more information

If you have any questions or comments about this advisory please contact Dane E. via dane@[project name].io.

Severity

High

CVE ID

No known CVE

Weaknesses

No CWEs