First published: Thu Mar 23 2023(Updated: )
A vulnerability, which was classified as critical, was found in novel-plus 3.6.2. Affected is the function MenuService of the file sys/menu/list. The manipulation of the argument sort leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-223662 is the identifier assigned to this vulnerability.
Credit: cna@vuldb.com cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Xxyopen Novel-plus | =3.6.2 | |
=3.6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-1594 is critical.
CVE-2023-1594 affects the function MenuService of the file sys/menu/list in novel-plus 3.6.2.
The vulnerability type of CVE-2023-1594 is SQL injection.
Yes, CVE-2023-1594 can be exploited remotely.
To fix CVE-2023-1594, apply the patch or upgrade to a fixed version of novel-plus.