SQL Injection Vulnerability in Novel-Plus by Novel-Plus Team
CVE-2022-35121
9.8CRITICAL
What is CVE-2022-35121?
A SQL injection vulnerability was identified in Novel-Plus version 3.6.1, allowing attackers to manipulate database queries through the 'keyword' parameter in the BookServiceImpl.java file. Exploiting this vulnerability can lead to unauthorized data access or modifications.