Description

Novel-Plus up to 5.2.4 was discovered to contain a Stored Cross-Site Scripting (XSS) vulnerability via the /author/updateIndexName endpoint. This vulnerability allows authenticated attackers to inject malicious JavaScript code through the indexName parameter, which gets stored in the database and executed when other users view the affected book chapter.

INFO

Published Date :

2025-10-08T00:00:00.000Z

Last Modified :

2025-10-08T14:54:01.058Z

Source :

mitre
AFFECTED PRODUCTS

The following products are affected by CVE-2025-60298 vulnerability.

Vendors Products
Novel-plus
  • Novel-plus
Xxyopen
  • Novel-plus
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-60298.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact