CVE-2025-6535: xxyopen/201206030 novel-plus User Management Module UserMapper.xml list sql injection
A vulnerability has been found in xxyopen/201206030 novel-plus up to 5.1.3 and classified as critical. This vulnerability affects the function list of the file novel-admin/src/main/resources/mybatis/system/UserMapper.xml of the component User Management Module. The manipulation of the argument sort/order leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-6535?
CVE-2025-6535 is classified as a critical vulnerability.
How does CVE-2025-6535 affect the User Management Module?
CVE-2025-6535 affects the function list in the UserMapper.xml file within the User Management Module.
What versions of xxyopen Novel-Plus are affected by CVE-2025-6535?
CVE-2025-6535 affects xxyopen Novel-Plus versions up to and including 5.1.3.
What action should be taken to mitigate CVE-2025-6535?
To mitigate CVE-2025-6535, it is recommended to update to a version of xxyopen Novel-Plus that is not vulnerable.
Is there a known exploit for CVE-2025-6535?
Yes, there are indications that exploit code may be available for CVE-2025-6535.