Novell-Plus SQL Injection Vulnerability
CVE-2024-24018
9.8CRITICAL
What is CVE-2024-24018?
A SQL injection vulnerability has been identified in the Novel-Plus application, specifically affecting version 4.3.0-RC1 and earlier releases. An attacker may exploit this vulnerability by supplying specially crafted parameters, such as offset, limit, and sort commands, through the /system/dataPerm/list endpoint. Successful exploitation can lead to unauthorized access to database information, making it crucial for users of affected versions to apply necessary security patches or mitigations.