Novel Plus
Products
1- 34 CVEs
Recent CVEs
34| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-25274 | Cri | 0.64 | 9.8 | 0.01 | Feb 20, 2024 | An arbitrary file upload vulnerability in the component /sysFile/upload of Novel-Plus v4.3.0-RC1 allows attackers to execute arbitrary code via uploading a crafted file. | ||
| CVE-2024-24021 | Cri | 0.64 | 9.8 | 0.01 | Feb 8, 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/userFeedback/list. | ||
| CVE-2024-24017 | Cri | 0.64 | 9.8 | 0.01 | Feb 8, 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /common/dict/list | ||
| CVE-2024-24014 | Cri | 0.64 | 9.8 | 0.01 | Feb 8, 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /novel/author/list | ||
| CVE-2024-24026 | Cri | 0.64 | 9.8 | 0.01 | Feb 8, 2024 | An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions at com.java2nb.system.controller.SysUserController: uploadImg(). An attacker can pass in specially crafted filename parameter to perform arbitrary File download. | ||
| CVE-2024-24024 | Cri | 0.64 | 9.8 | 0.01 | Feb 8, 2024 | An arbitrary File download vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: fileDownload(). An attacker can pass in specially crafted filePath and fieName parameters to perform arbitrary File download. | ||
| CVE-2024-24019 | Cri | 0.64 | 9.8 | 0.01 | Feb 7, 2024 | A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL injection via /system/roleDataPerm/list | ||
| CVE-2023-46981 | Cri | 0.64 | 9.8 | 0.01 | Nov 5, 2023 | SQL injection vulnerability in Novel-Plus v.4.2.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /common/log/list. | ||
| CVE-2023-30058 | Cri | 0.64 | 9.8 | 0.01 | Sep 11, 2023 | novel-plus 3.6.2 is vulnerable to SQL Injection. | ||
| CVE-2023-37847 | Cri | 0.64 | 9.8 | 0.01 | Aug 14, 2023 | novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability. | ||
| CVE-2022-36672 | Cri | 0.64 | 9.8 | 0.01 | Sep 1, 2022 | Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability allows attackers to create a custom user session. | ||
| CVE-2022-35121 | Cri | 0.64 | 9.8 | 0.01 | Aug 17, 2022 | Novel-Plus v3.6.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /service/impl/BookServiceImpl.java. | ||
| CVE-2021-42967 | Cri | 0.64 | 9.8 | 0.01 | May 13, 2022 | Unrestricted file upload in /novel-admin/src/main/java/com/java2nb/common/controller/FileController.java in novel-plus all versions allows allows an attacker to upload malicious JSP files. | ||
| CVE-2021-41921 | Cri | 0.64 | 9.8 | 0.02 | Apr 28, 2022 | novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution. | ||
| CVE-2024-33383 | Hig | 0.49 | 7.5 | 0.01 | Apr 30, 2024 | Arbitrary File Read vulnerability in novel-plus 4.3.0 and before allows a remote attacker to obtain sensitive information via a crafted GET request using the filePath parameter. | ||
| CVE-2022-36671 | Hig | 0.49 | 7.5 | 0.00 | Sep 1, 2022 | Novel-Plus v3.6.2 was discovered to contain an arbitrary file download vulnerability via the background file download API. | ||
| CVE-2022-28462 | Hig | 0.49 | 7.5 | 0.01 | May 5, 2022 | novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability. | ||
| CVE-2023-1594 | Hig | 0.48 | 7.3 | 0.01 | Mar 23, 2023 | A vulnerability, which was classified as critical, was found in novel-plus 3.6.2. Affected is the function MenuService of the file sys/menu/list. The manipulation of the argument sort leads to sql injection. It is possible to launch the attack remotely. The exploit has been… | ||
| CVE-2025-4019 | Hig | 0.47 | 7.3 | 0.01 | Apr 28, 2025 | A vulnerability, which was classified as critical, was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. Affected is the function genCode of the file novel-admin/src/main/java/com/java2nb/common/controller/GeneratorController.java. The manipulation… | ||
| CVE-2023-41443 | Hig | 0.47 | 7.2 | 0.01 | Sep 18, 2023 | SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /sys/menu/list. |
- risk 0.64cvss 9.8epss 0.01
An arbitrary file upload vulnerability in the component /sysFile/upload of Novel-Plus v4.3.0-RC1 allows attackers to execute arbitrary code via uploading a crafted file.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior. An attacker can pass specially crafted offset, limit, and sort parameters to perform SQL injection via /novel/userFeedback/list.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /common/dict/list
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /novel/author/list
- risk 0.64cvss 9.8epss 0.01
An arbitrary File upload vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions at com.java2nb.system.controller.SysUserController: uploadImg(). An attacker can pass in specially crafted filename parameter to perform arbitrary File download.
- risk 0.64cvss 9.8epss 0.01
An arbitrary File download vulnerability exists in Novel-Plus v4.3.0-RC1 and prior at com.java2nb.common.controller.FileController: fileDownload(). An attacker can pass in specially crafted filePath and fieName parameters to perform arbitrary File download.
- risk 0.64cvss 9.8epss 0.01
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL injection via /system/roleDataPerm/list
- risk 0.64cvss 9.8epss 0.01
SQL injection vulnerability in Novel-Plus v.4.2.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /common/log/list.
- risk 0.64cvss 9.8epss 0.01
novel-plus 3.6.2 is vulnerable to SQL Injection.
- risk 0.64cvss 9.8epss 0.01
novel-plus v3.6.2 was discovered to contain a SQL injection vulnerability.
- risk 0.64cvss 9.8epss 0.01
Novel-Plus v3.6.2 was discovered to contain a hard-coded JWT key located in the project config file. This vulnerability allows attackers to create a custom user session.
- risk 0.64cvss 9.8epss 0.01
Novel-Plus v3.6.1 was discovered to contain a SQL injection vulnerability via the keyword parameter at /service/impl/BookServiceImpl.java.
- risk 0.64cvss 9.8epss 0.01
Unrestricted file upload in /novel-admin/src/main/java/com/java2nb/common/controller/FileController.java in novel-plus all versions allows allows an attacker to upload malicious JSP files.
- risk 0.64cvss 9.8epss 0.02
novel-plus V3.6.1 allows unrestricted file uploads. Unrestricted file suffixes and contents can lead to server attacks and arbitrary code execution.
- risk 0.49cvss 7.5epss 0.01
Arbitrary File Read vulnerability in novel-plus 4.3.0 and before allows a remote attacker to obtain sensitive information via a crafted GET request using the filePath parameter.
- risk 0.49cvss 7.5epss 0.00
Novel-Plus v3.6.2 was discovered to contain an arbitrary file download vulnerability via the background file download API.
- risk 0.49cvss 7.5epss 0.01
novel-plus 3.6.0 suffers from an Arbitrary file reading vulnerability.
- risk 0.48cvss 7.3epss 0.01
A vulnerability, which was classified as critical, was found in novel-plus 3.6.2. Affected is the function MenuService of the file sys/menu/list. The manipulation of the argument sort leads to sql injection. It is possible to launch the attack remotely. The exploit has been…
- risk 0.47cvss 7.3epss 0.01
A vulnerability, which was classified as critical, was found in 20120630 Novel-Plus up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. Affected is the function genCode of the file novel-admin/src/main/java/com/java2nb/common/controller/GeneratorController.java. The manipulation…
- risk 0.47cvss 7.2epss 0.01
SQL injection vulnerability in Novel-Plus v.4.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /sys/menu/list.