First published: Thu Sep 01 2022(Updated: )
Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability allows attackers to create a custom user session.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Xxyopen Novel-plus | =3.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36672 is a vulnerability in Novel-Plus v3.6.2 that allows attackers to create a custom user session by exploiting a hard-coded JWT key located in the project config file.
CVE-2022-36672 has a severity rating of critical with a score of 9.8.
Novel-Plus v3.6.2 is affected by CVE-2022-36672.
To fix CVE-2022-36672, it is recommended to update Novel-Plus to a version that does not have the hard-coded JWT key or apply a patch provided by the vendor.
You can find more information about CVE-2022-36672 at [https://www.mesec.cn/archives/296](https://www.mesec.cn/archives/296).