CVE-2022-36672: Critical severity xxyopen novel-plus vulnerability
Published Sep 1, 2022
·Updated
Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability allows attackers to create a custom user session.
Affected Software
1 affected component
xxyopen Novel-Plus=3.6.2
Event History
Sep 1, 2022
CVE Published
via MITRE·02:08 AM
Data Sourced
via MITRE·02:08 AM
Description
Frequently Asked Questions
1
What is CVE-2022-36672?
CVE-2022-36672 is a vulnerability in Novel-Plus v3.6.2 that allows attackers to create a custom user session by exploiting a hard-coded JWT key located in the project config file.
2
How severe is CVE-2022-36672?
CVE-2022-36672 has a severity rating of critical with a score of 9.8.
3
What software is affected by CVE-2022-36672?
Novel-Plus v3.6.2 is affected by CVE-2022-36672.
4
How can CVE-2022-36672 be fixed?
To fix CVE-2022-36672, it is recommended to update Novel-Plus to a version that does not have the hard-coded JWT key or apply a patch provided by the vendor.
5
Where can I find more information about CVE-2022-36672?
You can find more information about CVE-2022-36672 at [https://www.mesec.cn/archives/296](https://www.mesec.cn/archives/296).