CRITICAL🇵🇱 Wersja polska

CVE-2025-22144

CVSS 9.0v4.0pub. 2025-01-13upd. 2025-05-13

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. A user with admincp.core.emails or admincp.users.edit permissions can validate users and an attacker can reset their password. When the account is successfully approved by email the reset code is NULL, but when the account is manually validated by a user with admincp.core.emails or admincp.users.edit permissions then the reset_code will no longer be NULL but empty. An attacker can request http://localhost/nameless/index.php?route=/forgot_password/&c= and reset the password. As a result an attacker may compromise another users password and take over their account. This issue has been addressed in release version 2.1.3 and all users are advised to upgrade. There are no known workarounds for this vulnerability.

🤖 AI Analysis
How it works

When a user account is approved via email, the reset_code field in the database is set to NULL. However, when an account is manually approved by a user with admincp.core.emails or admincp.users.edit permissions, the reset_code field is not NULL, but rather empty (an empty string). An attacker can send an HTTP request to the forgot_password endpoint with an empty c parameter (e.g., index.php?route=/forgot_password/&c=), which the system incorrectly interprets as a valid password reset code. As a result, the attacker gains the ability to set a new password for the victim's account without any additional verification.

Impact

An attacker can take control of any user account manually approved by an administrator by changing its password without the account owner's knowledge.

Mitigation & patch

Update NamelessMC to version 2.1.3 or later. The vendor reports that no known workarounds for this vulnerability exist — updating is the only recommended solution.

Who is affected

NamelessMC (Nameless) — versions prior to 2.1.3

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Namelessmc Nameless

    APP
    Namelessmc
    < 2.1.3
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-54117CRITICAL9.0PL ✓same product

XSS w edytorze tekstu panelu administracyjnego NamelessMC

CVE-2025-54421HIGH7.2same product

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS...

CVE-2025-31118HIGH7.1same product

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prio...

CVE-2025-30158HIGH7.1same product

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prio...

CVE-2025-29784HIGH7.5same product

NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prio...