PT-2025-18060 · Unknown · Novel-Plus
Aibot88
·
Published
2025-04-28
·
Updated
2025-10-17
·
CVE-2025-4015
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Novel-Plus versions 20120630 through 0e156c04b4b7ce0563bef6c97af4476fcda8f160
Description
A critical issue has been found that affects the function list of the file
novel-system/src/main/java/com/java2nb/system/controller/SessionController.java. This issue leads to missing authentication and can be exploited remotely. The exploit has been publicly disclosed, and the vendor was contacted prior to disclosure but did not respond.Recommendations
For Novel-Plus versions 20120630 through 0e156c04b4b7ce0563bef6c97af4476fcda8f160, as a temporary workaround, consider disabling the
SessionController.java file until a patch is available. Restrict access to the SessionController.java function list to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
Missing Authentication
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Novel-Plus