CVE-2025-4018
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Apr 28, 2025
Updated: Apr 29, 2025
CWE ID 287
CWE ID 306
Summary
CVE-2025-4018 is a critical vulnerability affecting Novel-Plus, versions up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. It lies in the "addCrawlSource" function of the file "novel-crawl/src/main/java/com/java2nb/novel/controller/CrawlController.java." This issue results in missing authentication, enabling remote attackers to exploit the flaw. Although the vendor was notified, they have yet to respond or take action to address the issue publicly disclosed vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.