SQL Injection Vulnerability in Novel-Plus by Novel-Plus Team
CVE-2023-41443
7.2HIGH
What is CVE-2023-41443?
An SQL injection vulnerability exists in Novel-Plus version 4.1.0, which could be exploited by a remote attacker. By crafting a specific script targeting the sort parameter in the /sys/menu/list endpoint, an attacker can execute arbitrary SQL commands, potentially compromising the integrity of the database and allowing unauthorized control over the application.