Description
novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that allows authenticated backend accounts to export complete book text including paid chapters. Attackers can supply a bookId and bookName to retrieve all chapter content without VIP or purchase verification, bypassing the permission checks and data-scope limits enforced elsewhere in the admin interface.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized export of full book text including paid chapters
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in novel‑plus versions up to 5.3.3 allows an authenticated backend user to bypass the intended authorization checks on the BookController download endpoint. By supplying a bookId and a bookName, the attacker can download the entire content of a book, including chapters that are normally restricted to paid or VIP users. This flaw effectively removes the protection layers that the administrative interface otherwise enforces, enabling data exfiltration that should be limited to authorized personnel only. The primary impact is a confidentiality breach that compromises revenue models and potentially publishes paid content without permission.

Affected Systems

All installations of the novel‑plus web application running version 5.3.3 or earlier. The affected product is identified as Novel‑plus by the vendor 201206030, and the vulnerability resides in the backend BookController component. System administrators should verify whether their deployment matches or precedes the released 5.3.3 version and assess if older revisions are in use.

Risk and Exploitability

The CVSS score of 5.3 classifies this flaw as moderate. EPSS data is not available, but absence of exploitation reports and its absence from the CISA KEV catalog suggest a low probability of immediate exploitation. The vulnerability once authenticated, the deleted authorization check allows the attacker to download any book's full text without VIP or purchase verification. Thus the attack surface is limited to users with administrative access, but the impact is a confidential data leak and revenue loss.

Generated by OpenCVE AI on September 15, 2026 at 13:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Apply the vendor‑released patch or upgrade to any later release of novel‑plus that addresses the authorization bypass.
  • Restrict network access to the administrative interface using segmentation or VPN to limit exposure to authorized personnel only.
  • Enable comprehensive logging and monitoring for download activity on the BookController endpoint to detect unauthorized data exfiltration.

Generated by OpenCVE AI on September 15, 2026 at 13:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 14:15:00 +0000

Type Values Removed Values Added
Description novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that allows authenticated backend accounts to export complete book text including paid chapters. Attackers can supply a bookId and bookName to retrieve all chapter content without VIP or purchase verification, bypassing the permission checks and data-scope limits enforced elsewhere in the admin interface.
Title novel-plus through 5.3.3 Missing Authorization on the Admin Book Download Endpoint
First Time appeared Xxyopen
Xxyopen novel-plus
Weaknesses CWE-862
CPEs cpe:2.3:a:xxyopen:novel-plus:*:*:*:*:*:*:*:*
Vendors & Products Xxyopen
Xxyopen novel-plus
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Xxyopen Novel-plus
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:02.877Z

Reserved: 2026-09-14T11:34:24.687Z

Link: CVE-2026-90941

cve-icon Vulnrichment

Updated: 2026-09-16T15:04:00.823Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T14:17:20.553

Modified: 2026-09-23T17:17:47.650

Link: CVE-2026-90941

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:00:11Z

Weaknesses