CVE-2025-4016
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Apr 28, 2025
Updated: Apr 29, 2025
CWE ID 285
CWE ID 266
Summary
CVE-2025-4016 is a newly disclosed critical vulnerability affecting Novel-Plus versions up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. The issue lies in the deleteIndex function of the file novel-admin/src/main/java/com/java2nb/common/controller/LogController.java. This vulnerability enables improper authorization, allowing remote manipulation. The exploit has been made public and the vendor, despite being contacted, has not responded. Users are urged to take immediate action to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.