CVE-2025-45890: Path Traversal
Published Jun 20, 2025
·Updated
Directory Traversal vulnerability in novel plus before v.5.1.0 allows a remote attacker to execute arbitrary code via the filePath parameter
Affected Software
2 affected components
novel plus novel plus<5.1.0
xxyopen Novel-Plus<5.1.0
Event History
Jun 20, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-45890?
The severity of CVE-2025-45890 is considered high due to its potential to allow remote code execution.
2
How do I fix CVE-2025-45890?
To fix CVE-2025-45890, update Novel Plus to version 5.1.0 or later.
3
What types of attacks can exploit CVE-2025-45890?
CVE-2025-45890 can be exploited in directory traversal attacks that manipulate the filePath parameter.
4
What versions of Novel Plus are affected by CVE-2025-45890?
CVE-2025-45890 affects all versions of Novel Plus prior to 5.1.0.
5
Who is at risk from CVE-2025-45890?
Remote attackers can exploit CVE-2025-45890 to gain unauthorized access to systems using affected versions of Novel Plus.