CVE-2025-4019
CVSS 2.0 Score 7.5 of 10 (high)
Details
Published Apr 28, 2025
Updated: Apr 29, 2025
CWE ID 287
CWE ID 306
Summary
CVE-2025-4019 is a critical vulnerability discovered in Novel-Plus versions up to 0e156c04b4b7ce0563bef6c97af4476fcda8f160. This issue lies in the genCode function of the file novel-admin/src/main/java/com/java2nb/common/controller/GeneratorController.java. The flaw results in missing authentication, allowing remote attackers to exploit it. Although the vendor was informed about the public disclosure of this exploit, they have yet to respond with a patch or remediation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.