Pterodactyl is a free, open-source game server management panel. Using the /locales/locale.json with the locale and namespace query parameters, a malicious actor is able to execute arbitrary code without being authenticated.
Log in to view the POC file snapshot cached by Shenlong Bot
Log in to view