Novel-Plus 5.3.3 及之前版本在 BookController 的下载端点中存在一个授权绕过漏洞,允许已认证的后端账户导出完整的书籍文本,包括付费章节。攻击者只需提供 bookId 和 bookName 即可获取所有章节内容,无需 VIP 或购买验证,从而绕过了管理界面其他位置所执行的权限检查和数据范围限制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| 201206030 | novel-plus | 0 ~ 5.3.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90939 | 6.5 MEDIUM | novel-plus through 5.3.3 Missing Authorization on the Admin /sys/user/list Endpoint |
| CVE-2026-90940 | 5.3 MEDIUM | novel-plus through 5.3.3 Default Cache Management Password in the Front Portal |
No comments yet