VYPR
Critical severity9.8NVD Advisory· Published Sep 1, 2022· Updated Jun 17, 2026

CVE-2022-36672

CVE-2022-36672

Description

Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability allows attackers to create a custom user session.

Affected products

2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.