CVE-2024-24014: SQL Injection
Published Feb 8, 2024
·Updated
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /novel/author/list
Affected Software
2 affected components
xxyopen Novel-Plus<=4.2.0
xxyopen Novel-Plus=4.3.0-rc1
Event History
Feb 8, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-24014?
The severity of CVE-2024-24014 is considered critical due to the potential for SQL injection exploitation.
2
How do I fix CVE-2024-24014?
To fix CVE-2024-24014, upgrade to Novel-Plus version 4.3.0-RC2 or later to patch the SQL injection vulnerability.
3
What versions are affected by CVE-2024-24014?
CVE-2024-24014 affects Novel-Plus versions up to and including 4.2.0 and 4.3.0-RC1.
4
What exploit can be performed with CVE-2024-24014?
An attacker can exploit CVE-2024-24014 to execute arbitrary SQL queries by manipulating the offset, limit, and sort parameters.
5
Is authentication required to exploit CVE-2024-24014?
No, authentication is not required to exploit CVE-2024-24014, making it particularly dangerous.