CVE-2025-60298 - Novel-Plus up to 5.2.4 was discovered to contain a
CVE ID : CVE-2025-60298
Published : Oct. 8, 2025, 1:15 p.m. | 1 hour, 57 minutes ago
Description : Novel-Plus up to 5.2.4 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /author/updateIndexName endpoint. This vulnerability allows authenticated attackers to inject malicious JavaScript code through the indexName parameter, which gets stored in the database and executed when other users view the affected book chapter.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Oct. 8, 2025, 1:15 p.m. | 1 hour, 57 minutes ago
Description : Novel-Plus up to 5.2.4 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /author/updateIndexName endpoint. This vulnerability allows authenticated attackers to inject malicious JavaScript code through the indexName parameter, which gets stored in the database and executed when other users view the affected book chapter.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...