CVE-2021-41176 is a cross-site request forgery (CSRF) vulnerability affecting the Pterodactyl game server management panel. A malicious actor can force a logged-in user to sign out by tricking them into visiting a crafted website that sends a request to the panel's logout endpoint. This attack has a low impact, as it only results in a user logout and does not compromise user data or leak sensitive information. The vulnerability has a CVSS score of 4.3 (Medium) and is not known to be actively exploited, nor is there publicly available exploit code or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.3CPE matchmatch criteria | cpe:2.3:a:pterodactyl:panel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.