PT-2026-45801 · Unknown · Namelessmc

·

CVE-2026-35447

·

Published

2026-06-02

·

Updated

2026-06-02

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions NamelessMC versions prior to 2.2.5
Description The profile page located at 'modules/Core/pages/profile.php' processes wall post submissions and replies before verifying if the viewer is authorized to access the profile. This allows users with the profile.post permission to write wall posts to profiles that are private or have blocked them. Furthermore, the reply mechanism fails to verify that the target wall post belongs to the current profile, which enables attackers to inject replies into wall posts owned by other profiles using a restricted profile URL.
Recommendations Update to version 2.2.5.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-35447
GHSA-C9XJ-RXGW-G2HQ

Affected Products

Namelessmc