5.3
CVE-2025-54118
- EPSS 0.4%
- Veröffentlicht 18.08.2025 16:15:29
- Zuletzt bearbeitet 20.08.2025 21:23:34
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
NamelessMC allows sensitive information disclosure in member list component
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. Sensitive information disclosure in NamelessMC before 2.2.4 allows unauthenticated remote attacker to gain sensitive information such as absolute path of the source code via list parameter. This vulnerability is fixed in 2.2.4.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Namelessmc ≫ Nameless Version < 2.2.4
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.4% | 0.315 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
https://github.com/NamelessMC/Nameless/commit/3b94eb594dcbb1abc5524e41a0631df3ac95de8f
https://github.com/NamelessMC/Nameless/security/advisories/GHSA-cj37-8jqc-hv2w