Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass crafted offset, limit, and sort parameters to perform SQL injection via /novel/pay/list
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Novel-Plus 安全漏洞
Vulnerability Description
Novel-Plus是Novel-Plus公司的一个在线社交阅读和写作平台。 Novel-Plus v4.3.0-RC1版本及之前版本存在安全漏洞。攻击者利用该漏洞可以传递特制的偏移、限制和排序参数,通过 /novel/pay/list 执行 SQL 注入攻击。
CVSS Information
N/A
Vulnerability Type
N/A