First published: Fri Apr 18 2025(Updated: )
NamelessMC is a free, easy to use & powerful website software for Minecraft servers. In version 2.1.4 and prior, the forum allows users to post iframe elements inside forum topics/comments/feed with no restriction on the iframe's width and height attributes. This allows an authenticated attacker to perform a UI-based denial of service (DoS) by injecting oversized iframes that block the forum UI and disrupt normal user interactions. This issue has been patched in version 2.2.0.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
NamelessMC | <2.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-30158 is considered a moderate severity vulnerability due to the potential for unauthorized content embedding.
To fix CVE-2025-30158, upgrade to NamelessMC version 2.2.0 or later.
NamelessMC versions up to and including 2.1.4 are affected by CVE-2025-30158.
CVE-2025-30158 can facilitate cross-site scripting (XSS) attacks through unrestricted iframe embedding.
Currently, there is no known workaround for CVE-2025-30158, and updating is strongly recommended.