CVE-2025-60299: XSS
Novel-Plus with 5.2.0 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /book/addCommentReply endpoint. An authenticated user can inject malicious JavaScript through the replyContent parameter when replying to a book comment. The payload is stored in the database and is executed in other users’ browsers when they view the affected comment thread.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-60299?
CVE-2025-60299 is classified as a high-severity vulnerability due to its potential for stored cross-site scripting attacks.
How do I fix CVE-2025-60299?
To fix CVE-2025-60299, validate and sanitize the input in the replyContent parameter to prevent malicious code injection.
Who is affected by CVE-2025-60299?
CVE-2025-60299 affects users of Novel-Plus version 5.2.0.
What type of vulnerability is CVE-2025-60299?
CVE-2025-60299 is a Stored Cross-Site Scripting (XSS) vulnerability.
Can CVE-2025-60299 affect my application if I am not using Novel-Plus?
No, CVE-2025-60299 specifically affects the Novel-Plus application version 5.2.0.