SQL Injection Vulnerability in Novel-Plus Application by Novel-Plus Development Team
CVE-2024-24015

9.8CRITICAL

Key Information:

Vendor

Xxyopen

Vendor
CVE Published:
6 February 2024

What is CVE-2024-24015?

A SQL injection vulnerability has been identified in the Novel-Plus application affecting versions up to and including v4.3.0-RC1. This vulnerability allows attackers to manipulate SQL queries by passing specially crafted parameters through the /sys/user/exit endpoint. Exploitation of this flaw could enable unauthorized access to sensitive information stored in the database, potentially leading to data breaches and unauthorized data manipulation. Mitigating this risk involves applying the latest updates or patches provided by the vendor.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-24015 : SQL Injection Vulnerability in Novel-Plus Application by Novel-Plus Development Team