First published: Thu Jan 18 2024(Updated: )
A vulnerability has been found in Novel-Plus 4.3.0-RC1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /novel/bookSetting/list. The manipulation of the argument sort leads to sql injection. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-251383.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
xxyopen Novel | =4.3.0-rc1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-0655 is classified as a critical vulnerability.
To fix CVE-2024-0655, it is advised to upgrade Novel-Plus to a patched version that addresses the SQL injection vulnerability.
CVE-2024-0655 can facilitate SQL injection attacks, allowing an attacker to manipulate the database.
Novel-Plus version 4.3.0-RC1 is affected by CVE-2024-0655.
The vulnerability CVE-2024-0655 is associated with the file /novel/bookSetting/list.