Sensitive Information Disclosure in NamelessMC Website Software for Minecraft Servers
CVE-2025-54118
5.3MEDIUM
What is CVE-2025-54118?
NamelessMC, a versatile website software designed for Minecraft servers, contains a vulnerability that allows unauthorized remote access to sensitive information. Prior to version 2.2.4, attackers could exploit this flaw to reveal critical details, including the absolute path of the source code, through manipulated request parameters. It is crucial for users to upgrade to the latest version to safeguard their servers against potential data leaks.
Affected Version(s)
Nameless < 2.2.4