SQL Injection Vulnerability in NamelessMC Website Software
CVE-2025-32389
6.5MEDIUM
What is CVE-2025-32389?
NamelessMC is an open-source website software designed for Minecraft servers, which was found to be vulnerable to SQL injection through an unexpected square bracket GET parameter syntax. This vulnerability allows attackers to manipulate database queries by exploiting the structure typically used in PHP, namely ?param[0]=a¶m[1]=b¶m[2]=c, leading to unauthorized access to sensitive information. Users are strongly encouraged to upgrade to version 2.1.4 or later, which addresses this security flaw.
