Executive brief
NamelessMC is a popular website software used by Minecraft server communities to manage forums and user accounts. A security flaw allows any logged-in user to bypass privacy settings and read messages in restricted areas, such as private staff-only forums. This could lead to the exposure of sensitive administrative discussions or private member data.
Technical details
An improper authorization vulnerability (CWE-285) exists in the `get_quotes.php` module of NamelessMC version 2.2.4. While the standard topic view enforces Access Control Lists (ACLs), the `get_quotes` endpoint only verifies that a user is logged in before fetching post content via an attacker-supplied `post` ID. Because the backend helper in `Forum.php` fails to validate forum or topic-level permissions, a low-privileged user can enumerate post IDs to leak content and author metadata from restricted, hidden, or staff-only forums. This issue is resolved in version 2.2.5.
Affected products
- NamelessMC NamelessMC 2.2.4
Timeline
- 2026-05-31: advisory: GitHub Security Advisory published
- 2026-06-02: disclosed: CVE published to NVD