CVE-2023-46981: SQL Injection
Published Nov 4, 2023
·Updated
SQL injection vulnerability in Novel-Plus v.4.2.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /common/log/list.
Affected Software
1 affected component
xxyopen Novel-Plus=4.2.0
Event History
Nov 4, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Nov 5, 2023
Data Sourced
via NVD·12:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2023-46981?
CVE-2023-46981 is a SQL injection vulnerability in Novel-Plus v.4.2.0.
2
What software is affected by CVE-2023-46981?
Novel-Plus v.4.2.0 is affected by CVE-2023-46981.
3
How can a remote attacker exploit CVE-2023-46981?
A remote attacker can exploit CVE-2023-46981 by executing arbitrary code via a crafted script to the sort parameter in /common/log/list.
4
What is the severity of CVE-2023-46981?
CVE-2023-46981 has a severity rating of 9.8 (Critical).
5
How can I fix CVE-2023-46981?
To fix CVE-2023-46981, update to a version of Novel-Plus that is not affected by the vulnerability.