NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS) vulnerability in NamelessMC before 2.2.3 allows remote authenticated attackers to inject arbitrary web script or HTML via the dashboard text editor component. This vulnerability is fixed in 2.2.4.
The vulnerability consists of insufficient sanitization of input data entered by a logged-in user in the text editor component (dashboard text editor). An attacker with content editing permissions can embed malicious script or HTML code that will be executed in the browser of another victim when viewing the infected page. Due to the scope change (Scope: Changed), the impact of the attack may extend beyond the session of the directly attacked user. The vulnerability is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation) and CWE-80 (Improper Neutralization of Script-Related HTML Tags).
An attacker can hijack a user or administrator session, steal confidential data and perform unauthorized actions on behalf of the victim, which may lead to complete takeover of the Minecraft server website.
NamelessMC should be immediately updated to version 2.2.4, where the vulnerability has been fixed. The fix commit is available at: https://github.com/NamelessMC/Nameless/commit/0e77706b2966dd9f2e30502126d6581ecc001f09
NamelessMC in versions before 2.2.3 (vulnerability removed in version 2.2.4)
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:HNamelessmc Nameless
APPNamelessmc< 2.2.4
Related vulnerabilities
NamelessMC — przejęcie konta przez pusty kod resetowania hasła
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Cross-site scripting (XSS...
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prio...
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prio...
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prio...