Critical severity9.8NVD Advisory· Published Nov 5, 2023· Updated Jun 17, 2026
CVE-2023-46981
CVE-2023-46981
Description
SQL injection vulnerability in Novel-Plus v.4.2.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /common/log/list.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:xxyopen:novel-plus:4.2.0:*:*:*:*:*:*:*
- Novel-Plus/Novel-Plusdescription
- Range: =4.2.0
Patches
Vulnerability mechanics
References
1- github.com/JunFengDeng/Cve-List/blob/main/novel-plus/20231027/vuln/readme.mdnvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.