Home
CRITICAL: 10.0 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:HDefault status
unaffected
Any version
affected
Description
OGP-Website installs prior git commit 52f865a4fba763594453068acf8fa9e3fc38d663 are affected by a type juggling flaw which if exploited can result in authentication bypass without knowledge of the victim account's password.
Problem types
CWE-287 Improper Authentication
Product status
Any version
References
github.com/...ommit/52f865a4fba763594453068acf8fa9e3fc38d663
github.com/OpenGamePanel/OGP-Website/pull/644
projectblack.io/blog/vibe-hacking-open-game-panel-rce/