Impact
The flaw is caused by missing permission annotations on the /sys/user/list endpoint in novel-plus up to version 5.3.3. An authenticated user can invoke this endpoint and receive password hashes as well as personal data such as email addresses and phone numbers. The weakness is classified as CWE-862, indicating insufficient authorization checks. The immediate effect is that an attacker can acquire credential material for offline hash cracking and potentially takeover user accounts.
Affected Systems
The vulnerable product is novel-plus, released by 201206030. The issue exists in all releases up to and including version 5.3.3. Attempts to run the endpoint in later versions are unaffected once the patch has been applied.
Risk and Exploitability
The CVSS score of 7.1 places the vulnerability in the medium‑high and the flaw is not listed in the CISA KEV catalog. Because the attack requires only valid authentication and does not need elevated privileges, any authenticated user with access to the system can exploit it. The resulting data exposure facilitates offline password cracking and enables account takeover.
OpenCVE Enrichment