CVE-2023-2040: novel-plus sql injection
A vulnerability classified as critical has been found in novel-plus 3.6.2. Affected is an unknown function of the file /news/list?limit=10&offset=0&order=desc. The manipulation of the argument sort leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-225918 is the identifier assigned to this vulnerability. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-2040?
CVE-2023-2040 is a critical vulnerability found in novel-plus 3.6.2.
What is the severity of CVE-2023-2040?
CVE-2023-2040 has a severity rating of 8.8 (high).
How does CVE-2023-2040 affect novel-plus 3.6.2?
CVE-2023-2040 affects an unknown function of the file /news/list?limit=10&offset=0&order=desc in novel-plus 3.6.2, allowing for remote SQL injection attacks.
Is CVE-2023-2040 exploitable remotely?
Yes, CVE-2023-2040 can be exploited remotely.
How can I fix CVE-2023-2040 in novel-plus 3.6.2?
To fix CVE-2023-2040, update novel-plus to a version that addresses the SQL injection vulnerability.