Impact
The vulnerability in novel‑plus versions up to 5.3.3 allows an authenticated backend user to bypass the intended authorization checks on the BookController download endpoint. By supplying a bookId and a bookName, the attacker can download the entire content of a book, including chapters that are normally restricted to paid or VIP users. This flaw effectively removes the protection layers that the administrative interface otherwise enforces, enabling data exfiltration that should be limited to authorized personnel only. The primary impact is a confidentiality breach that compromises revenue models and potentially publishes paid content without permission.
Affected Systems
All installations of the novel‑plus web application running version 5.3.3 or earlier. The affected product is identified as Novel‑plus by the vendor 201206030, and the vulnerability resides in the backend BookController component. System administrators should verify whether their deployment matches or precedes the released 5.3.3 version and assess if older revisions are in use.
Risk and Exploitability
The CVSS score of 5.3 classifies this flaw as moderate. EPSS data is not available, but absence of exploitation reports and its absence from the CISA KEV catalog suggest a low probability of immediate exploitation. The vulnerability once authenticated, the deleted authorization check allows the attacker to download any book's full text without VIP or purchase verification. Thus the attack surface is limited to users with administrative access, but the impact is a confidential data leak and revenue loss.
OpenCVE Enrichment