CVE-2024-33383: High severity novel-plus vulnerability
Published Apr 30, 2024
·Updated
Arbitrary File Read vulnerability in novel-plus 4.3.0 and before allows a remote attacker to obtain sensitive information via a crafted GET request using the filePath parameter.
Affected Software
2 affected components
novel-plus novel-plus<4.3.0
xxyopen Novel-Plus<=4.3.0
Event History
Apr 30, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-33383?
CVE-2024-33383 is classified as a medium severity vulnerability.
2
How does CVE-2024-33383 affect users of novel-plus?
CVE-2024-33383 allows a remote attacker to read arbitrary files on the server, potentially exposing sensitive information.
3
How can I mitigate CVE-2024-33383?
To mitigate CVE-2024-33383, upgrade to a version of novel-plus later than 4.3.0 to eliminate the vulnerability.
4
What versions of novel-plus are affected by CVE-2024-33383?
CVE-2024-33383 affects all versions of novel-plus up to and including 4.3.0.
5
What type of request is exploited in CVE-2024-33383?
CVE-2024-33383 is exploited via crafted GET requests using the filePath parameter.