CVE-2022-35121: SQL Injection
Published Aug 17, 2022
·Updated
Novel-Plus v3.6.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /service/impl/BookServiceImpl.java.
Affected Software
1 affected component
xxyopen Novel-Plus=3.6.1
Event History
Aug 17, 2022
CVE Published
via MITRE·07:43 PM
Data Sourced
via MITRE·07:43 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this SQL injection vulnerability?
The vulnerability ID for this SQL injection vulnerability is CVE-2022-35121.
2
What is the severity of CVE-2022-35121?
The severity of CVE-2022-35121 is critical (9.8 out of 10).
3
How does the SQL injection vulnerability occur in Novel-Plus v3.6.1?
The SQL injection vulnerability in Novel-Plus v3.6.1 occurs via the keyword parameter at /service/impl/BookServiceImpl.java.
4
What software version is affected by CVE-2022-35121?
The software version affected by CVE-2022-35121 is Novel-Plus v3.6.1.
5
Is there a fix available for this vulnerability?
Yes, it is recommended to update to a patched version of Novel-Plus that addresses the SQL injection vulnerability.