Novel-Plus up to 5.2.4 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /author/updateIndexName endpoint. This vulnerability allows authenticated attackers to inject malicious JavaScript code through the indexName parameter, which gets stored in the database and executed when other users view the affected book chapter.
References
| Link | Resource |
|---|---|
| https://github.com/201206030/novel-plus | Product |
| https://notes.sjtu.edu.cn/s/FB0dX82qf | Exploit Third Party Advisory |
| https://notes.sjtu.edu.cn/s/FB0dX82qf# | Exploit Third Party Advisory |
Configurations
History
10 Oct 2025, 16:18
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/201206030/novel-plus - Product | |
| References | () https://notes.sjtu.edu.cn/s/FB0dX82qf - Exploit, Third Party Advisory | |
| References | () https://notes.sjtu.edu.cn/s/FB0dX82qf# - Exploit, Third Party Advisory | |
| CPE | cpe:2.3:a:xxyopen:novel-plus:*:*:*:*:*:*:*:* | |
| First Time |
Xxyopen
Xxyopen novel-plus |
08 Oct 2025, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-79 | |
| References |
|
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
08 Oct 2025, 13:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-08 13:15
Updated : 2025-10-10 16:18
NVD link : CVE-2025-60298
Mitre link : CVE-2025-60298
CVE.ORG link : CVE-2025-60298
JSON object : View
Products Affected
xxyopen
- novel-plus
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
