PT-2026-91245 · Unknown · Novel-Plus
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
novel-plus versions prior to 5.3.4
Description
An authorization bypass exists in the
download endpoint of the BookController. This issue allows authenticated backend accounts to export the complete text of a book, including paid chapters, by providing a bookId and bookName. The flaw enables the retrieval of all chapter content by bypassing VIP or purchase verification, as well as permission checks and data-scope limits typically enforced within the admin interface.Recommendations
Update novel-plus to version 5.3.4 or later.
As a temporary mitigation, restrict access to the
download endpoint in the BookController to prevent unauthorized exports.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Novel-Plus