Cross-Site Scripting Vulnerability in NamelessMC Website Software for Minecraft Servers
CVE-2025-22142

5.4MEDIUM

Key Information:

Vendor

NamelessMC

Vendor
CVE Published:
13 January 2025

What is CVE-2025-22142?

NamelessMC, a widely used website software for Minecraft servers, is vulnerable to a Cross-Site Scripting attack due to improper handling of user input in an additional field added by admin. Malicious users can exploit this by injecting JavaScript code that gets executed when a staff member views the user's profile. This poses serious risks since it can lead to unauthorized access and manipulation of sensitive information. The issue has been effectively resolved in version 2.1.3, and users are strongly encouraged to update to this version, as no workaround exists for this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

.