PT-2026-45773 · Unknown · Namelessmc
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
NamelessMC version 2.2.4
Description
An issue exists where the endpoint
modules/Forum/pages/forum/get quotes.php only verifies if a user is logged in before retrieving a post based on the post variable. The backend helper in modules/Forum/classes/Forum.php fails to enforce Access Control Lists (ACLs)—which are sets of rules that define permissions for users or systems—for forums or topics. This allows authenticated users with low privileges to enumerate post IDs and access content from private, hidden, or staff-only forums, bypassing the visibility restrictions enforced in modules/Forum/pages/forum/view topic.php.Recommendations
Update NamelessMC to version 2.2.5.
Exploit
Fix
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Namelessmc