CVE-2024-47765 - CVE House
Back to Database
Status published Medium CVE-2024-47765

Minecraft MOTD Parser's HtmlGenerator vulnerable to XSS

Vulnerability Description

Minecraft MOTD Parser is a PHP library to parse minecraft server motd. The HtmlGenerator class is subject to potential cross-site scripting (XSS) attack through a parsed malformed Minecraft server MOTD. The HtmlGenerator iterates through objects of MotdItem that are contained in an object of MotdItemCollection to generate a HTML string. An attacker can make malicious inputs to the color and text properties of MotdItem to inject own HTML into a web page during web page generation. For example by sending a malicious MOTD from a Minecraft server under their control that was queried and passed to the HtmlGenerator. This XSS vulnerability exists because the values of these properties are neither filtered nor escaped. This vulnerability is fixed in 1.0.6.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-47765

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

MinecraftMotdParser
Vulnerable Versions:
< 1.0.6

Timeline

Official Publish: October 4th, 2024
Last Modified: October 4th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)