Remote Code Execution Vulnerability in xxyopen Novel Plus from Vendor xxyopen
CVE-2025-26182

6.5MEDIUM

Key Information:

Vendor

xxyopen

Vendor
CVE Published:
4 March 2025

What is CVE-2025-26182?

A vulnerability in xxyopen Novel Plus allows attackers to execute arbitrary code remotely by manipulating the PageController.java file. This poses a serious security risk, as unauthorized code execution can lead to compromise of sensitive data and system integrity. Organizations using affected versions must apply updates promptly to mitigate this threat.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.