VDB
CVE-2025-4036
CVE-2025-4036
PUBLISHED
CVSS 5.300000190734863 MEDIUM
A vulnerability was found in 201206030 Novel 3.5.0 and classified as critical. This issue affects the function updateBookChapter of the file src/main/java/io/github/xxyopen/novel/controller/author/AuthorController.java of the component Chapter Handler. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
EPSS 0.34% · 57.0th percentile
Risk Scores
CVSS 4.0
5.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
EPSS Score
0.34%
57.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| xxyopen | novel | 3.5.0 |
| 201206030 | Novel | 3.5.0 |
Exploit Intelligence
- CIRCL seen: CVE-2025-4036 (circl-sighting)
- CIRCL seen: CVE-2025-4036 (circl-sighting)
- VDB-306401 | 201206030 Novel Chapter AuthorController.java updateBookChapter access control (circl)
- VDB-306401 | CTI Indicators (IOB, IOC, TTP, IOA) (circl)
- Submit #558414 | xxyopen novel V3.5.0 Improper Access Controls (circl)
- https://github.com/Sinon2003/cve/blob/main/novel/Novel%20%20has%20a%20logic%20authorization%20bypass%20vulnerability%20in%20AuthorController.md (cve.org)
Timeline
- Apr 28, 2025 Coalition ESS Score
- Apr 28, 2025 Coalition ESS Score
- Apr 28, 2025 CVE Published
- Apr 28, 2025 PoC Published
- Apr 29, 2025 EPSS Score
- Apr 29, 2025 Coalition ESS Score
- Apr 29, 2025 PoC Published
- May 10, 2025 Coalition ESS Score
- May 10, 2025 CVE Updated
- May 11, 2025 EPSS Score
- May 23, 2025 EPSS Score
- Jun 4, 2025 EPSS Score
References
- VDB-306401 | 201206030 Novel Chapter AuthorController.java updateBookChapter access control vdb
- VDB-306401 | CTI Indicators (IOB, IOC, TTP, IOA) url
- Submit #558414 | xxyopen novel V3.5.0 Improper Access Controls third-party-advisory
- https://github.com/Sinon2003/cve/blob/main/novel/Novel%20%20has%20a%20logic%20authorization%20bypass%20vulnerability%20in%20AuthorController.md exploit
- https://nvd.nist.gov/vuln/detail/CVE-2025-4036 advisory