CVE-2025-54118

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Sensitive information disclosure in NamelessMC before 2.2.4 allows unauthenticated remote attacker to gain sensitive information such as absolute path of the source code via list parameter. This vulnerability is fixed in 2.2.4.
Configurations

Configuration 1 (hide)

cpe:2.3:a:namelessmc:nameless:*:*:*:*:*:*:*:*

History

20 Aug 2025, 21:23

Type Values Removed Values Added
References () https://github.com/NamelessMC/Nameless/commit/3b94eb594dcbb1abc5524e41a0631df3ac95de8f - () https://github.com/NamelessMC/Nameless/commit/3b94eb594dcbb1abc5524e41a0631df3ac95de8f - Patch
References () https://github.com/NamelessMC/Nameless/security/advisories/GHSA-cj37-8jqc-hv2w - () https://github.com/NamelessMC/Nameless/security/advisories/GHSA-cj37-8jqc-hv2w - Exploit, Vendor Advisory
CPE cpe:2.3:a:namelessmc:nameless:*:*:*:*:*:*:*:*
First Time Namelessmc nameless
Namelessmc
Summary
  • (es) NamelessMC es un software web gratuito, fácil de usar y potente para servidores de Minecraft. La divulgación de información confidencial en NamelessMC anterior a la versión 2.2.4 permite que un atacante remoto no autenticado obtenga información confidencial, como la ruta absoluta del código fuente, mediante el parámetro de lista. Esta vulnerabilidad se corrige en la versión 2.2.4.

18 Aug 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-08-18 16:15

Updated : 2025-08-20 21:23


NVD link : CVE-2025-54118

Mitre link : CVE-2025-54118

CVE.ORG link : CVE-2025-54118


JSON object : View

Products Affected

namelessmc

  • nameless
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor