Description
novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL path. Attackers can trigger unauthorized cache invalidation by accessing the cache/refresh endpoint with the known default password, forcing unnecessary database queries to repopulate the cache.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Mon, 14 Sep 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL path. Attackers can trigger unauthorized cache invalidation by accessing the cache/refresh endpoint with the known default password, forcing unnecessary database queries to repopulate the cache. | |
| Title | novel-plus through 5.3.3 Default Cache Management Password in the Front Portal | |
| First Time appeared |
Xxyopen
Xxyopen novel-plus |
|
| Weaknesses | CWE-1392 | |
| CPEs | cpe:2.3:a:xxyopen:novel-plus:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xxyopen
Xxyopen novel-plus |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-14T13:58:43.612Z
Reserved: 2026-09-14T11:34:24.687Z
Link: CVE-2026-90940
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-1392
Use of Default Credentials