CVE-2025-22144 is a critical vulnerability affecting NamelessMC, a website software for Minecraft servers. It allows an unauthenticated attacker to reset any user's password by exploiting a flaw in the manual account validation process, where the password reset code becomes empty instead of NULL. This vulnerability carries a CVSS score of 9.8 (CRITICAL), indicating a high potential for complete compromise of user accounts due to its network-based attack vector and low complexity. While there are no known active exploits, public exploit code, or significant community discussion, the high severity warrants immediate patching. Users are strongly advised to upgrade to NamelessMC version 2.1.3 to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.1.3CPE matchmatch criteria | cpe:2.3:a:namelessmc:nameless:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.