CVE-2025-4019

CVSS 2.0 Score 7.5 of 10 (high)

Details

Published Apr 28, 2025
Updated: Apr 29, 2025
CWE ID 287
CWE ID 306

Summary

CVE-2025-4019 is a critical vulnerability discovered in Novel-Plus versions up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This issue lies in the genCode function of the file novel-admin/src/main/java/com/java2nb/common/controller/GeneratorController.java. The flaw results in missing authentication, allowing remote attackers to exploit it. Although the vendor was informed about the public disclosure of this exploit, they have yet to respond with a patch or remediation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share