CVE-2025-54118 Information

Description

NamelessMC is a free easy to use & powerful website software for Minecraft servers. Sensitive information disclosure in NamelessMC before 2.2.4 allows unauthenticated remote attacker to gain sensitive information such as absolute path of the source code via list parameter. This vulnerability is fixed in 2.2.4.

Reference

https://github.com/NamelessMC/Nameless/commit/3b94eb594dcbb1abc5524e41a0631df3ac95de8f https://github.com/NamelessMC/Nameless/security/advisories/GHSA-cj37-8jqc-hv2w

CNNVD-202508-2025 (Published: 2025-08-18)

Share on: