CVE-2025-31120
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Apr 18, 2025
Updated: May 13, 2025
CWE ID 565
Summary
CVE-2025-31120 is a vulnerability affecting the NamelessMC software used for Minecraft servers. In versions 2.1.4 and below, an insecure view count mechanism in the forum page allows unauthenticated attackers to artificially inflate the view count. The application incorrectly relies on a client-side cookie or session variable for view tracking. Whenever an attacker does not provide the necessary cookie, each page request results in the counter being incremented, leading to inaccurate view metrics. This issue has been resolved in version 2.2.0.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Vendors
- Namelessmc