CVE-2023-1594: novel-plus list MenuService sql injection
Published Mar 23, 2023
·Updated
A vulnerability, which was classified as critical, was found in novel-plus 3.6.2. Affected is the function MenuService of the file sys/menu/list. The manipulation of the argument sort leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-223662 is the identifier assigned to this vulnerability.
Affected Software
1 affected component
xxyopen Novel-Plus=3.6.2
Event History
Mar 23, 2023
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-1594?
The severity of CVE-2023-1594 is critical.
2
How does CVE-2023-1594 affect novel-plus 3.6.2?
CVE-2023-1594 affects the function MenuService of the file sys/menu/list in novel-plus 3.6.2.
3
What is the vulnerability type of CVE-2023-1594?
The vulnerability type of CVE-2023-1594 is SQL injection.
4
Is CVE-2023-1594 remotely exploitable?
Yes, CVE-2023-1594 can be exploited remotely.
5
How can I fix CVE-2023-1594?
To fix CVE-2023-1594, apply the patch or upgrade to a fixed version of novel-plus.