Medium severity5.4NVD Advisory· Published Oct 8, 2025· Updated Jun 17, 2026
CVE-2025-60299
CVE-2025-60299
Description
Novel-Plus with 5.2.0 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /book/addCommentReply endpoint. An authenticated user can inject malicious JavaScript through the replyContent parameter when replying to a book comment. The payload is stored in the database and is executed in other users’ browsers when they view the affected comment thread.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:xxyopen:novel-plus:5.2.0:*:*:*:*:*:*:*
(expand)+ 1 more
- (no CPE)
- (no CPE)range: =5.2.0
Patches
Vulnerability mechanics
References
1- notes.sjtu.edu.cn/s/OtnFaGbI4nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.