Pterodactyl Panel 在 1.14.1 版本之前,在创建计划任务时未对特定操作进行权限校验,导致仅拥有 权限的子用户可以执行任意控制台命令。攻击者可以创建并立即触发计划任务,从而运行游戏服务器控制台命令、控制服务器的电源状态,或创建备份,而系统未进行适当的授权检查。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| pterodactyl | panel | < 1.14.1 |
affected |
1.14.1 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pterodactyl | panel | 0 ~ 1.14.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet