Vulnerability Details
Basic Information
| Title | CVE-2025-31118 NamelessMC Has Forum Reply Submission Time Limit Bypass |
|---|---|
| Type | cvelist |
| Published | 2025-04-18T15:52:36 |
| Last Seen | 2025-04-18T16:17:16 |
| CVSS Score | 7.1 (HIGH) |
CVSS v3 Details
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | NONE |
| Integrity Impact | LOW |
| Availability Impact | HIGH |
CVE Information
| CVE IDs | CVE-2025-31118 |
|---|---|
| CWE | CWE-400 |
| Bulletin Family | cve |
Description
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, forum quick reply feature (view_topic.php) does not implement any spam prevention mechanism. This allows authenticated users to continuously post replies without any time restriction, resulting in an uncontrolled surge of posts that can disrupt normal operations. This issue has been patched in version 2.2.0.
Impact Assessment
| Base Score | 7.1 |
|---|---|
| Severity | HIGH |