novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that allows authenticated backend accounts to export complete book text including paid chapters. Attackers can supply a bookId and bookName to retrieve all chapter content without VIP or purchase verification, bypassing the permission checks and data-scope limits enforced elsewhere in the admin interface.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 14 Sep 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | novel-plus through 5.3.3 contains an authorization bypass vulnerability in the BookController download endpoint that allows authenticated backend accounts to export complete book text including paid chapters. Attackers can supply a bookId and bookName to retrieve all chapter content without VIP or purchase verification, bypassing the permission checks and data-scope limits enforced elsewhere in the admin interface. | |
| Title | novel-plus through 5.3.3 Missing Authorization on the Admin Book Download Endpoint | |
| First Time appeared |
Xxyopen
Xxyopen novel-plus |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:xxyopen:novel-plus:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xxyopen
Xxyopen novel-plus |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-14T13:58:44.268Z
Reserved: 2026-09-14T11:34:24.687Z
Link: CVE-2026-90941
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses