novel-plus list MenuService sql injection
CVE-2023-1594
7.3HIGH
What is CVE-2023-1594?
A security flaw has been identified in Novel-Plus 3.6.2, where improper handling of the 'sort' argument in the MenuService function can lead to an SQL injection attack. This vulnerability allows a remote attacker to manipulate SQL queries, potentially leading to unauthorized data access and execution of arbitrary database commands. The vulnerability has been exposed publicly, heightening the risk for affected installations.
Affected Version(s)
novel-plus 3.6.2