NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Prior to version 2.1.4, NamelessMC is vulnerable to SQL injection by providing an unexpected square bracket GET parameter syntax. Square bracket GET parameter syntax refers to the structure `?param[0]=a&param[1]=b&param[2]=c` utilized by PHP, which is parsed by PHP as `$_GET['param']` being of type array. This issue has been patched in version 2.1.4.
History

Tue, 13 May 2025 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Namelessmc
Namelessmc nameless
CPEs cpe:2.3:a:namelessmc:nameless:*:*:*:*:*:*:*:*
Vendors & Products Namelessmc
Namelessmc nameless
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Fri, 18 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Prior to version 2.1.4, NamelessMC is vulnerable to SQL injection by providing an unexpected square bracket GET parameter syntax. Square bracket GET parameter syntax refers to the structure `?param[0]=a&param[1]=b&param[2]=c` utilized by PHP, which is parsed by PHP as `$_GET['param']` being of type array. This issue has been patched in version 2.1.4.
Title NamelessMC Vulnerable to SQL Injections in /user/messaging and /panel/users/reports Pages
Weaknesses CWE-89
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-04-18T15:56:39.962Z

Updated: 2025-04-18T16:24:24.300Z

Reserved: 2025-04-06T19:46:02.463Z

Link: CVE-2025-32389

cve-icon Vulnrichment

Updated: 2025-04-18T16:15:16.987Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-18T16:15:23.033

Modified: 2025-05-13T15:23:15.957

Link: CVE-2025-32389

cve-icon Redhat

No data.