Vulnerabilities (CVE)

Filtered by vendor Xxyopen Subscribe
Filtered by product Novel-plus
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-46981 1 Xxyopen 1 Novel-plus 2023-11-13 N/A 9.8 CRITICAL
SQL injection vulnerability in Novel-Plus v.4.2.0 allows a remote attacker to execute arbitrary code via a crafted script to the sort parameter in /common/log/list.