Unknown · Novel-Plus · CVE-2025-45890
Name of the Vulnerable Software and Affected Versions:
novel plus versions prior to 5.1.0
Description:
A Directory Traversal issue allows a remote attacker to execute arbitrary code via the `filePath` parameter. This enables the attacker to potentially access and manipulate files outside the intended directory structure.
Recommendations:
For versions prior to 5.1.0, update to version 5.1.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the `filePath` parameter to minimize the risk of exploitation.