No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 02 Jun 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Namelessmc
Namelessmc nameless |
|
| Vendors & Products |
Namelessmc
Namelessmc nameless |
Tue, 02 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 02 Jun 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/classes/ForumPostReactionContext.php` only verifies that the caller can view the forum, but it does not re-enforce topic-level `view_other_topics` authorization. As a result, in forums where users may enter the forum but may only view their own topics, reactions can still be read and modified on other users' topics. Version 2.2.5 fixes the issue. | |
| Title | NamelessMC: Forum reactions bypass the "view own topics only" restriction | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-06-02T15:50:06.670Z
Reserved: 2026-04-02T19:25:52.192Z
Link: CVE-2026-35443
Updated: 2026-06-02T18:06:50.008Z
Status : Deferred
Published: 2026-06-02T17:16:28.283
Modified: 2026-06-02T17:18:38.120
Link: CVE-2026-35443
No data.
OpenCVE Enrichment
Updated: 2026-06-02T18:30:15Z