Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hqxh-9xh6-r77j

Опубликовано: 14 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.9
CVSS3: 5.3

Описание

novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL path. Attackers can trigger unauthorized cache invalidation by accessing the cache/refresh endpoint with the known default password, forcing unnecessary database queries to repopulate the cache.

novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL path. Attackers can trigger unauthorized cache invalidation by accessing the cache/refresh endpoint with the known default password, forcing unnecessary database queries to repopulate the cache.

EPSS

Процентиль: 24%
0.00311
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-1392

Связанные уязвимости

CVSS3: 5.3
nvd
6 дней назад

novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL path. Attackers can trigger unauthorized cache invalidation by accessing the cache/refresh endpoint with the known default password, forcing unnecessary database queries to repopulate the cache.

EPSS

Процентиль: 24%
0.00311
Низкий

6.9 Medium

CVSS4

5.3 Medium

CVSS3

Дефекты

CWE-1392