A SQL injection vulnerability exists in Novel-Plus v4.3.0-RC1 and prior versions. An attacker can pass in crafted offset, limit, and sort parameters to perform SQL via /sys/user/exit
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 20 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-06-20T20:14:17.158Z
Reserved: 2024-01-25T00:00:00.000Z
Link: CVE-2024-24015
Updated: 2024-08-01T23:19:51.330Z
Status : Modified
Published: 2024-02-06T16:15:52.410
Modified: 2025-06-20T21:15:21.197
Link: CVE-2024-24015
No data.
OpenCVE Enrichment
No data.
Weaknesses