SQL Injection Vulnerability in Novel-Plus by JunFengDeng
CVE-2023-46981
9.8CRITICAL
What is CVE-2023-46981?
The SQL injection vulnerability in Novel-Plus version 4.2.0 permits a remote attacker to execute arbitrary code. This can be exploited through manipulation of the sort parameter within the /common/log/list endpoint, leading to potential unauthorized access and compromise of the web application.