CVE-2025-60298: XSS
Novel-Plus up to 5.2.4 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /author/updateIndexName endpoint. This vulnerability allows authenticated attackers to inject malicious JavaScript code through the indexName parameter, which gets stored in the database and executed when other users view the affected book chapter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60298?
CVE-2025-60298 is classified as a moderate severity Stored Cross-Site Scripting (XSS) vulnerability.
How do I fix CVE-2025-60298?
To fix CVE-2025-60298, update Novel-Plus to version 5.2.5 or later.
Who is affected by CVE-2025-60298?
CVE-2025-60298 affects all versions of Novel-Plus up to and including 5.2.4.
What type of vulnerability is CVE-2025-60298?
CVE-2025-60298 is a Stored Cross-Site Scripting (XSS) vulnerability.
What can an attacker do with CVE-2025-60298?
An authenticated attacker can inject malicious JavaScript code through the indexName parameter via the /author/updateIndexName endpoint.