Vulnerability Details
Basic Information
| Title | CVE-2025-30357 NamelessMC Forum Topic Deletion Triggered by Unrelated User Deletion |
|---|---|
| Type | cvelist |
| Published | 2025-04-18T15:51:21 |
| Last Seen | 2025-04-18T16:09:50 |
| CVSS Score | 7.3 (HIGH) |
CVSS v3 Details
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | HIGH |
| Privileges Required | HIGH |
| User Interaction | REQUIRED |
| Scope | CHANGED |
| Confidentiality Impact | NONE |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
CVE Information
| CVE IDs | CVE-2025-30357 |
|---|---|
| CWE | CWE-706 |
| Bulletin Family | cve |
Description
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, if a malicious user is leaving spam comments on many topics then an administrator, unable to manually remove each spam comment, may delete the malicious account. Once an administrator deletes the malicious user’s account, all their posts (comments) along with the associated topics (by unrelated users) will be marked as deleted. This issue has been patched in version 2.2.0.
Impact Assessment
| Base Score | 7.3 |
|---|---|
| Severity | HIGH |