SQL Injection Vulnerability in Novel-Plus by Novel Technologies
CVE-2024-24013
9.8CRITICAL
What is CVE-2024-24013?
A SQL injection vulnerability exists in Novel-Plus, specifically in versions v4.3.0-RC1 and earlier. This vulnerability allows attackers to exploit crafted offset, limit, and sort parameters, potentially leading to unauthorized access to sensitive database information. By targeting the endpoint /novel/pay/list, adversaries can manipulate database queries, posing significant risks to the integrity and confidentiality of user data.