A vulnerability was found in Novel-Plus up to 4.2.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file novel-admin/src/main/java/com/java2nb/novel/controller/FriendLinkController.java of the component Friendly Link Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The patch is named d6093d8182362422370d7eaf6c53afde9ee45215. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-249307.
[
{
"id": "CVE-2023-7171-626563b9",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "novel-admin/src/main/java/com/java2nb/novel/controller/FriendLinkController.java"
},
"source": "https://github.com/201206030/novel-plus/commit/d6093d8182362422370d7eaf6c53afde9ee45215",
"signature_type": "Line",
"digest": {
"line_hashes": [
"7249178626788191660058062194464852161",
"145612411571589582893835794422037524202",
"183969095872355640598168705390787032137",
"56209659738649257552504804561745548465",
"234046354558881161097924841678785758144",
"98675930659164782737828200862021212167",
"183316133266311559314418765588333387000",
"314939173238408816761882483123554812045",
"29192670534613769320389366229368074968",
"13509165424030054875003723524643107929",
"323404673883367690967740862225754016114",
"161621567219547516124512110358084850340"
],
"threshold": 0.9
}
},
{
"id": "CVE-2023-7171-fa1d25ab",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "novel-admin/src/main/java/com/java2nb/novel/controller/FriendLinkController.java",
"function": "update"
},
"source": "https://github.com/201206030/novel-plus/commit/d6093d8182362422370d7eaf6c53afde9ee45215",
"signature_type": "Function",
"digest": {
"length": 162.0,
"function_hash": "293599672120823880177243680393520895893"
}
},
{
"id": "CVE-2023-7171-fe40b26b",
"signature_version": "v1",
"deprecated": false,
"target": {
"file": "novel-admin/src/main/java/com/java2nb/novel/domain/FriendLinkDO.java"
},
"source": "https://github.com/201206030/novel-plus/commit/d6093d8182362422370d7eaf6c53afde9ee45215",
"signature_type": "Line",
"digest": {
"line_hashes": [
"216176216332043677852855728591812921856",
"237701309485597711992628975952620124771",
"73513368532785297479889427851273810684",
"56049461750650145249837290371577838613",
"53185882450343332021933423679016545402",
"128651093876388659297711303418928564344",
"330570127507532594114039172860630144466",
"255725375665232561262820746560377102551",
"315998107380987406772442950610247700950",
"50818768278640860156591669769632299436",
"213471535135711828528395917387860886054",
"226064727670258840856665223434128451067",
"101057187101355890124800935343093357644",
"112434091802782599175858469722562107530",
"223529377569807000701826134604842315387",
"223806915562220579072543753071490033023",
"39058435622538381409020757610827383596",
"305000650980050999700811489288051834193",
"36554896989674533256526708747655538367",
"97188781382069985574975359731857050253",
"86662099509728494415071945464158777018",
"327555917390319089983808939561202742276",
"240951794247935870136278235338311666975",
"74491867004228301552221213951573745674",
"80853112392298221153967388094497941595",
"158784832469941241786031566204119428408",
"99822655194930673244098241197793673687",
"279635165208005852669129722064902764528",
"248857385538826757326917389468563989236",
"257584051421046443326126491686148097338",
"18996259688573344077960543655140316062",
"18341136536039283250018551236708980854",
"4029342667321193470159401939603255469",
"235288525702998524090288422649000773171",
"200433836052465607189738152707145134827",
"306061907267430193531603140924317425736",
"252907800415277969057552742920052534438",
"42145084641342487483066458577995226568",
"241730442992980224480339191720751259696",
"228262512128434643196861356041133191544",
"153282427664916353708779899585596250474",
"314530998816563662060035579481894091354",
"224732532345055280038354521625810614616",
"329535859610656442238207066289696301604",
"319227004211292937550303693923786973009",
"299075086949198824628769958904627776583",
"107367121873593110034115122782671392626",
"197786356455854246385886498041580713634",
"207509510933814492802286250861136391561",
"92038574541113714265002719843588452035",
"306665931738379110137188334515358023775",
"211267441811550375622103716661240691539",
"182736615662148500443147528712489127400",
"98512301472609610122447684209179080594",
"126668790730942505828203245506897587709",
"167218725457076662921964559429155737966",
"268172179125700718219935654759639196873",
"278723264555655567702666173544096215037",
"301811024929448183218604535263826361728",
"275453250383617998610561728448815437746",
"176451329167972135485067931500749330578",
"231265189101250153017587719278839914271",
"132797949374692876510021188769414742898",
"89821639318445068204047832380882677673",
"67871052699731480591781029023646161551",
"106111442447476088375614148746742047275",
"49345332378776146569519315483968341843",
"89887002849674075604338223683515914586",
"155365416661700476345813527574937748667",
"34278334402289486640973530915580792199",
"59294273542409529793547519125923064360",
"122226174527809774583569558771717803718",
"208577387239962598408754709464304529966",
"86840588782536771141928567557155932561"
],
"threshold": 0.9
}
}
]