PT-2026-86514 · Unknown · Pocketmine-Mp
CVE-2021-48006
·
Published
2021-12-16
·
Updated
2026-09-06
CVSS v4.0
4.8
Medium
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
PocketMine-MP versions prior to 4.0.3
Description
The
removeOp() function fails to perform case-insensitive matching when removing operator entries from the ops.txt file. While the function converts the supplied name to lowercase, it only removes entries that are an exact match. Consequently, if an operator name contains uppercase letters, the deop command cannot revoke their privileges, requiring the entry to be deleted manually from the file.Recommendations
Update to version 4.0.3 or later.
Exploit
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pocketmine-Mp