Stored Cross-Site Scripting Vulnerability in Novel-Plus Product by Unknown Vendor
CVE-2025-60299

5.4MEDIUM

Key Information:

Vendor
CVE Published:
8 October 2025

What is CVE-2025-60299?

A vulnerability has been identified in Novel-Plus version 5.2.0 that allows authenticated users to exploit the /book/addCommentReply endpoint. Through the replyContent parameter, attackers can inject malicious JavaScript code, which gets stored in the database. This payload is executed in the browsers of users who later view the affected comment thread, potentially compromising user sessions or revealing sensitive information.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.