NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the s parameter in GET requests for forum search functionality lacks length validation, allowing attackers to submit excessively long search queries. This oversight can lead to performance degradation and potential denial-of-service (DoS) attacks. This issue has been patched in version 2.2.0.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-11863 NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the s parameter in GET requests for forum search functionality lacks length validation, allowing attackers to submit excessively long search queries. This oversight can lead to performance degradation and potential denial-of-service (DoS) attacks. This issue has been patched in version 2.2.0.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 13 May 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Namelessmc
Namelessmc nameless
CPEs cpe:2.3:a:namelessmc:nameless:*:*:*:*:*:*:*:*
Vendors & Products Namelessmc
Namelessmc nameless

Fri, 18 Apr 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the s parameter in GET requests for forum search functionality lacks length validation, allowing attackers to submit excessively long search queries. This oversight can lead to performance degradation and potential denial-of-service (DoS) attacks. This issue has been patched in version 2.2.0.
Title NamelessMC Has Lack of Length Validation for s Parameter in GET Requests
Weaknesses CWE-1284
CWE-130
CWE-20
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-04-18T16:05:30.640Z

Reserved: 2025-03-11T14:23:00.475Z

Link: CVE-2025-29784

cve-icon Vulnrichment

Updated: 2025-04-18T16:05:20.433Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-18T16:15:22.163

Modified: 2025-05-13T15:41:25.090

Link: CVE-2025-29784

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.