NamelessMC
cpe:2.3:a:namelessmc:nameless:*:*:*:*:*:*:*
- <= 2.1.2
A vulnerability in NamelessMC versions through 2.1.2 allows for password resets and subsequent account takeovers. This issue arises when a user with 'admincp.core.emails' or 'admincp.users.edit' permissions manually validates another user. Unlike accounts validated via email, which receive a NULL reset code, manually validated accounts are assigned an empty reset code. An attacker can exploit this by requesting a password reset with the empty code, effectively taking over the account.
Exploitation of this vulnerability allows for unauthorized password resets, leading to account takeovers.
To reproduce this vulnerability, register an account and have a user with 'admincp.core.emails' or 'admincp.users.edit' permissions validate it. Once validated, the attacker can send a password reset request with an empty code, allowing them to reset the password and take over the account.
Users are advised to upgrade to NamelessMC version 2.1.3, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.