Stored Cross-Site Scripting Vulnerability in Novel-Plus Product by Unknown Vendor
CVE-2025-60299
5.4MEDIUM
What is CVE-2025-60299?
A vulnerability has been identified in Novel-Plus version 5.2.0 that allows authenticated users to exploit the /book/addCommentReply endpoint. Through the replyContent parameter, attackers can inject malicious JavaScript code, which gets stored in the database. This payload is executed in the browsers of users who later view the affected comment thread, potentially compromising user sessions or revealing sensitive information.