CVE-2025-60298

Novel-Plus up to 5.2.4 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /author/updateIndexName endpoint. This vulnerability allows authenticated attackers to inject malicious JavaScript code through the indexName parameter, which gets stored in the database and executed when other users view the affected book chapter.
References
Link Resource
https://github.com/201206030/novel-plus Product
https://notes.sjtu.edu.cn/s/FB0dX82qf Exploit Third Party Advisory
https://notes.sjtu.edu.cn/s/FB0dX82qf# Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:xxyopen:novel-plus:*:*:*:*:*:*:*:*

History

10 Oct 2025, 16:18

Type Values Removed Values Added
References () https://github.com/201206030/novel-plus - () https://github.com/201206030/novel-plus - Product
References () https://notes.sjtu.edu.cn/s/FB0dX82qf - () https://notes.sjtu.edu.cn/s/FB0dX82qf - Exploit, Third Party Advisory
References () https://notes.sjtu.edu.cn/s/FB0dX82qf# - () https://notes.sjtu.edu.cn/s/FB0dX82qf# - Exploit, Third Party Advisory
CPE cpe:2.3:a:xxyopen:novel-plus:*:*:*:*:*:*:*:*
First Time Xxyopen
Xxyopen novel-plus

08 Oct 2025, 15:16

Type Values Removed Values Added
CWE CWE-79
References
  • () https://notes.sjtu.edu.cn/s/FB0dX82qf# -
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

08 Oct 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-08 13:15

Updated : 2025-10-10 16:18


NVD link : CVE-2025-60298

Mitre link : CVE-2025-60298

CVE.ORG link : CVE-2025-60298


JSON object : View

Products Affected

xxyopen

  • novel-plus
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')