PT-2025-17314 · Unknown · Namelessmc

Vz0N

·

Published

2025-04-18

·

Updated

2025-04-18

·

CVE-2025-32389

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions NamelessMC versions prior to 2.1.4
Description The issue is related to SQL injection by providing an unexpected square bracket GET parameter syntax. This syntax refers to the structure ?param[0]=a&param[1]=b&param[2]=c utilized by PHP, which is parsed by PHP as $ GET['param'] being of type array.
Recommendations For versions prior to 2.1.4, update to version 2.1.4 to resolve the issue. As a temporary workaround, consider restricting access to API endpoints that utilize the square bracket GET parameter syntax until the update is applied. Avoid using the square bracket syntax in GET parameters for affected versions until the issue is resolved.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-32389
GHSA-5984-MHCP-CQ2X

Affected Products

Namelessmc