Cross-Site Scripting Vulnerability in NamelessMC Website Software for Minecraft Servers
CVE-2025-22142
5.4MEDIUM
What is CVE-2025-22142?
NamelessMC, a widely used website software for Minecraft servers, is vulnerable to a Cross-Site Scripting attack due to improper handling of user input in an additional field added by admin. Malicious users can exploit this by injecting JavaScript code that gets executed when a staff member views the user's profile. This poses serious risks since it can lead to unauthorized access and manipulation of sensitive information. The issue has been effectively resolved in version 2.1.3, and users are strongly encouraged to update to this version, as no workaround exists for this vulnerability.
