PT-2025-17314 · Unknown · Namelessmc
Vz0N
·
Published
2025-04-18
·
Updated
2025-04-18
·
CVE-2025-32389
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
NamelessMC versions prior to 2.1.4
Description
The issue is related to SQL injection by providing an unexpected square bracket GET parameter syntax. This syntax refers to the structure
?param[0]=a¶m[1]=b¶m[2]=c utilized by PHP, which is parsed by PHP as $ GET['param'] being of type array.Recommendations
For versions prior to 2.1.4, update to version 2.1.4 to resolve the issue. As a temporary workaround, consider restricting access to API endpoints that utilize the square bracket GET parameter syntax until the update is applied. Avoid using the square bracket syntax in GET parameters for affected versions until the issue is resolved.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Namelessmc