Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown
CVE-2025-22144
Disclosure Date: January 13, 2025 (last updated January 14, 2025)
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. A user with admincp.core.emails or admincp.users.edit permissions can validate users and an attacker can reset their password. When the account is successfully approved by email the reset code is NULL, but when the account is manually validated by a user with admincp.core.emails or admincp.users.edit permissions then the reset_code will no longer be NULL but empty. An attacker can request http://localhost/nameless/index.php?route=/forgot_password/&c= and reset the password. As a result an attacker may compromise another users password and take over their account. This issue has been addressed in release version 2.1.3 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2025-22142
Disclosure Date: January 13, 2025 (last updated January 14, 2025)
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In affected versions an admin can add the ability to have users fill out an additional field and users can inject javascript code into it that would be activated once a staffer visits the user's profile on staff panel. As a result an attacker can execute javascript code on the staffer's computer. This issue has been addressed in version 2.1.3 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
0
Attacker Value
Unknown
CVE-2022-2821
Disclosure Date: August 15, 2022 (last updated February 24, 2025)
Missing Critical Step in Authentication in GitHub repository namelessmc/nameless prior to v2.0.2.
0
Attacker Value
Unknown
CVE-2022-2820
Disclosure Date: August 15, 2022 (last updated February 24, 2025)
Session Fixation in GitHub repository namelessmc/nameless prior to v2.0.2.
0