CVE-2025-3369: xxyopen Novel-Plus list sql injection
Published Apr 7, 2025
·Updated
A vulnerability was found in xxyopen Novel-Plus 5.1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /novel/friendLink/list. The manipulation of the argument sort leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
2 affected components
xxyopen Novel-Plus
xxyopen Novel-Plus=5.1.0
Event History
Apr 7, 2025
CVE Published
via MITRE·01:31 PM
Data Sourced
via MITRE·01:31 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Nov 7, 57745
Event
via NVD·02:55 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-3369?
CVE-2025-3369 is rated as critical.
2
What vulnerability is associated with CVE-2025-3369?
CVE-2025-3369 is associated with a SQL injection vulnerability in the /novel/friendLink/list functionality.
3
What systems are affected by CVE-2025-3369?
CVE-2025-3369 affects the xxyopen Novel-Plus 5.1.0 application.
4
How do I fix CVE-2025-3369?
To fix CVE-2025-3369, ensure input validation and parameterized queries are implemented to prevent SQL injection.
5
Can CVE-2025-3369 be exploited remotely?
Yes, CVE-2025-3369 can be exploited remotely by manipulating the sort argument.