SQL Injection Vulnerability in Novel-Cloud by 201206030
CVE-2025-3956
5.3MEDIUM
What is CVE-2025-3956?
A SQL injection vulnerability exists in Novel-Cloud 1.4.0, specifically in the RestResp function of the BookInfoMapper.xml file. This flaw allows attackers to manipulate SQL queries, potentially leading to unauthorized data access or alteration. The vulnerability can be exploited remotely, making it a significant risk to users of the affected software. Despite early notification, the vendor has not responded to this critical issue, raising concerns about timely mitigation.
Affected Version(s)
novel-cloud 1.4.0
