CVE-2024-0941
- EPSS 0.05%
- Veröffentlicht 26.01.2024 19:15:08
- Zuletzt bearbeitet 21.11.2024 08:47:49
A vulnerability was found in Novel-Plus 4.3.0-RC1 and classified as critical. This issue affects some unknown processing of the file /novel/bookComment/list. The manipulation of the argument sort leads to sql injection. The exploit has been disclosed...
CVE-2024-0655
- EPSS 0.05%
- Veröffentlicht 18.01.2024 03:15:59
- Zuletzt bearbeitet 21.11.2024 08:47:05
A vulnerability has been found in Novel-Plus 4.3.0-RC1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /novel/bookSetting/list. The manipulation of the argument sort leads to sql injection. The explo...
CVE-2023-7171
- EPSS 0.1%
- Veröffentlicht 29.12.2023 18:15:39
- Zuletzt bearbeitet 21.11.2024 08:45:25
A vulnerability was found in Novel-Plus up to 4.2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file novel-admin/src/main/java/com/java2nb/novel/controller/FriendLinkController.java of the c...
CVE-2023-7166
- EPSS 0.13%
- Veröffentlicht 29.12.2023 09:15:09
- Zuletzt bearbeitet 21.11.2024 08:45:25
A vulnerability classified as problematic has been found in Novel-Plus up to 4.2.0. This affects an unknown part of the file /user/updateUserInfo of the component HTTP POST Request Handler. The manipulation of the argument nickName leads to cross sit...
CVE-2023-46981
- EPSS 1.02%
- Veröffentlicht 05.11.2023 00:15:08
- Zuletzt bearbeitet 21.11.2024 08:29:35
SQL injection vulnerability in Novel-Plus v.4.2.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /common/log/list.
CVE-2023-41443
- EPSS 0.89%
- Veröffentlicht 18.09.2023 22:15:47
- Zuletzt bearbeitet 21.11.2024 08:21:12
SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /sys/menu/list.
CVE-2023-30058
- EPSS 0.07%
- Veröffentlicht 11.09.2023 16:15:07
- Zuletzt bearbeitet 21.11.2024 07:59:45
novel-plus 3.6.2 is vulnerable to SQL Injection.
CVE-2023-37847
- EPSS 0.3%
- Veröffentlicht 14.08.2023 12:15:09
- Zuletzt bearbeitet 01.08.2025 02:09:57
novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.
CVE-2023-2041
- EPSS 0.05%
- Veröffentlicht 14.04.2023 09:15:07
- Zuletzt bearbeitet 21.11.2024 07:57:49
A vulnerability classified as critical was found in novel-plus 3.6.2. Affected by this vulnerability is an unknown functionality of the file /category/list?limit=10&offset=0&order=desc. The manipulation of the argument sort leads to sql injection. Th...
CVE-2023-2040
- EPSS 0.05%
- Veröffentlicht 14.04.2023 09:15:07
- Zuletzt bearbeitet 21.11.2024 07:57:48
A vulnerability classified as critical has been found in novel-plus 3.6.2. Affected is an unknown function of the file /news/list?limit=10&offset=0&order=desc. The manipulation of the argument sort leads to sql injection. It is possible to launch the...