CVE-2023-7171: Novel-Plus Friendly Link FriendLinkController.java cross site scripting
A vulnerability was found in Novel-Plus up to 4.2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file novel-admin/src/main/java/com/java2nb/novel/controller/FriendLinkController.java of the component Friendly Link Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The patch is named d6093d8182362422370d7eaf6c53afde9ee45215. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-249307.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-7171?
CVE-2023-7171 has been declared as problematic due to its potential impact on the Friendly Link Handler functionality.
How do I fix CVE-2023-7171?
To mitigate CVE-2023-7171, it is recommended to update Novel-Plus to version 4.2.1 or later.
What components are affected by CVE-2023-7171?
CVE-2023-7171 affects the Friendly Link Handler functionality in the file located at novel-admin/src/main/java/com/java2nb/novel/controller/FriendLinkController.java.
What versions of Novel-Plus are vulnerable to CVE-2023-7171?
CVE-2023-7171 affects all versions of Novel-Plus up to and including 4.2.0.
Is there a known exploit for CVE-2023-7171?
Details about known exploits for CVE-2023-7171 are not publicly available at this time.