PT-2025-17313 · Unknown · Namelessmc
Yuhano
·
Published
2025-04-18
·
Updated
2025-04-19
·
CVE-2025-31120
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
NamelessMC versions 2.1.4 and prior
Description
The issue concerns an insecure view count mechanism in the forum page of NamelessMC, a free website software for Minecraft servers. This mechanism relies on a client-side cookie (
nl-topic-[tid]) or a session variable for guests to determine if a view should be counted. When a client does not provide the cookie, every page request increments the counter, leading to incorrect view metrics.Recommendations
For versions 2.1.4 and prior, update to version 2.2.0 to resolve the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Namelessmc