VDB
Sign up
—0.0

GHSA-m49f-hcxp-6hm6

pterodactyl/panel CSRF allowing an external page to trigger a user logout event

Quick fix

GHSA-m49f-hcxp-6hm6 — pterodactyl/panel: upgrade to the fixed version with the command below.

composer require pterodactyl/panel:^1.6.3

Details

### Impact A malicious user can trigger a user logout if a signed in user visits a malicious website that makes a request to the Panel's sign-out endpoint. This requires a targeted attack against a specific Panel instance, and serves only to sign a user out. **No user details are leaked, nor is any user data affected, this is simply an annoyance at worst.**

### Patches None.

### Workarounds None.

### For more information If you have any questions or comments about this advisory please contact `Tactical Fish#8008` on Discord, or email `dane@pterodactyl.io`.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/pterodactyl/panel
Introduced in: 1.0.0Fixed in: 1.6.3
Fixcomposer require pterodactyl/panel:^1.6.3

References