PT-2026-45749 · Unknown · Namelessmc
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
NamelessMC version 2.2.4
Description
A Reflected Cross-Site Scripting (XSS) issue exists where the application reflects user-supplied input into the HTML response without proper sanitization or output encoding. This occurs at the endpoint "/index.php?route=/queries/user/" via the
id parameter. An attacker can craft a malicious URL containing JavaScript code that executes in the victim's browser, potentially leading to session hijacking, phishing attacks, or manipulation of page content.Recommendations
Update to version 2.2.5.
As a temporary workaround, avoid using the
id parameter in the "/index.php?route=/queries/user/" endpoint until the update is applied.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Namelessmc