CVE-2025-31120

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Apr 18, 2025
Updated: May 13, 2025
CWE ID 565

Summary

CVE-2025-31120 is a vulnerability affecting the NamelessMC software used for Minecraft servers. In versions 2.1.4 and below, an insecure view count mechanism in the forum page allows unauthenticated attackers to artificially inflate the view count. The application incorrectly relies on a client-side cookie or session variable for view tracking. Whenever an attacker does not provide the necessary cookie, each page request results in the counter being incremented, leading to inaccurate view metrics. This issue has been resolved in version 2.2.0.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share