Stored Cross-Site Scripting Vulnerability in Novel-Plus by 201206030
CVE-2025-60298

5.4MEDIUM

Key Information:

Vendor

201206030

Vendor
CVE Published:
8 October 2025

What is CVE-2025-60298?

A vulnerability has been identified in Novel-Plus where authenticated users can exploit the /author/updateIndexName endpoint to perform Stored Cross-Site Scripting (XSS). This issue allows attackers to inject and store malicious JavaScript code in the database through the indexName parameter. The injected script is executed when other users access the affected book chapter, posing risks of unauthorized actions or data theft. Users of Novel-Plus should review their security measures and update to newer versions to mitigate this risk.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.