Impact
An insecure default password is hard‑coded in the CacheController.refreshCache endpoint of the Novel Plus front portal. When an attacker supplies the known default value in the triggers a forced cache refresh. This causes the system to perform unnecessary database queries to rebuild the cache, potentially leading to resource exhaustion and degraded performance. The weakness is a hard‑coded credential, categorized as a hard‑coded password flaw.
Affected Systems
The vulnerability affects the Novel Plus web application, specifically versions up to and including 5.3.3. The source code for the affected releases contains a hard‑coded password in the CacheController and application configuration files, as shown in the public GitHub repository for version 5.3.3.
Risk and Exploitability
The CVSS score of 6.9 indicates medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires only unauthenticated HTTP access to the /cache/refresh endpoint and knowledge of the publicly known default password, making it a straightforward attack for an adversary with network access to the application.
OpenCVE Enrichment