Metrics
Affected Vendors & Products
Wed, 23 Apr 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Xxyopen
Xxyopen novel-plus |
|
CPEs | cpe:2.3:a:xxyopen:novel-plus:3.5.0:*:*:*:*:*:*:* | |
Vendors & Products |
Xxyopen
Xxyopen novel-plus |
Thu, 17 Apr 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 16 Apr 2025 08:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability classified as critical has been found in xxyopen Novel-Plus 3.5.0. This affects an unknown part of the file /api/front/search/books. The manipulation of the argument sort leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. | |
Title | xxyopen Novel-Plus books sql injection | |
Weaknesses | CWE-74 CWE-89 |
|
References |
| |
Metrics |
cvssV2_0
|

Status: PUBLISHED
Assigner: VulDB
Published: 2025-04-16T08:00:06.460Z
Updated: 2025-04-17T13:56:20.703Z
Reserved: 2025-04-16T00:56:26.242Z
Link: CVE-2025-3676

Updated: 2025-04-17T13:33:01.445Z

Status : Analyzed
Published: 2025-04-16T08:15:14.707
Modified: 2025-04-23T16:17:29.770
Link: CVE-2025-3676

No data.