[CVE-2025-15586] 氛围黑客:在Open Game Panel中发现认证绕过和RCE
projectblack.io | 研究 | CVE-2025-15586 | #rce | #authentication-bypass | #open-game-panel | #type-juggling | #cve-2025-15586
摘要
Open Game Panel 的「氛围黑客」实践:MD5 松散比较(==)导致的类型混淆漏洞可用 magic hash 密码登录(CVE-2025-15586),配合 Semgrep 发现的 LFI 可进一步升级为认证后 RCE。
- 发布时间
- 收录时间
Skip to content