CVE-2025-4018: 20120630 Novel-Plus CrawlController.java addCrawlSource missing authentication
A vulnerability, which was classified as critical, has been found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This issue affects the function addCrawlSource of the file novel-crawl/src/main/java/com/java2nb/novel/controller/CrawlController.java. The manipulation leads to missing authentication. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4018?
CVE-2025-4018 is classified as a critical severity vulnerability.
How does CVE-2025-4018 affect the software?
CVE-2025-4018 affects the addCrawlSource function in the CrawlController.java file within the Novel-Plus software.
How do I fix CVE-2025-4018?
To fix CVE-2025-4018, you should update your Novel-Plus software to version later than 0e156c04b4b7ce0563bef6c97af4476fcda8f160.
What versions of Novel-Plus are affected by CVE-2025-4018?
Novel-Plus versions up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160 are affected by CVE-2025-4018.
Is CVE-2025-4018 exploitable remotely?
Yes, CVE-2025-4018 is considered exploitable remotely.