Novel Plus 插件 5.3.3 及之前版本在 端点中存在不安全的默认缓存管理密码。匿名用户可通过在 URL 路径中提供硬编码的默认密码值,从而触发非授权的缓存失效攻击。攻击者利用已知的默认密码访问 端点,可强制系统执行不必要的数据库查询以重新填充缓存,从而发起未经授权的缓存失效操作。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| 201206030 | novel-plus | 0 ~ 5.3.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90939 | 6.5 MEDIUM | novel-plus through 5.3.3 Missing Authorization on the Admin /sys/user/list Endpoint |
| CVE-2026-90941 | 4.3 MEDIUM | novel-plus through 5.3.3 Missing Authorization on the Admin Book Download Endpoint |
No comments yet