CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-3956: 201206030 novel-cloud BookInfoMapper.xml RestResp sql injection

5.3 CVSS

Description

A vulnerability has been found in 201206030 novel-cloud 1.4.0 and classified as critical. This vulnerability affects the function RestResp of the file novel-cloud-master/novel-book/novel-book-service/src/main/resources/mapper/BookInfoMapper.xml. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. In 201206030 novel-cloud 1.4.0 wurde eine kritische Schwachstelle gefunden. Betroffen ist die Funktion RestResp der Datei novel-cloud-master/novel-book/novel-book-service/src/main/resources/mapper/BookInfoMapper.xml. Durch Manipulieren mit unbekannten Daten kann eine sql injection-Schwachstelle ausgenutzt werden. Der Angriff kann über das Netzwerk passieren. Der Exploit steht zur öffentlichen Verfügung.

Classification

CVE ID: CVE-2025-3956

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.3

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Problem Types

SQL Injection Injection

Affected Products

Vendor: 201206030

Product: novel-cloud

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.03% (probability of being exploited)

EPSS Percentile: 6.52% (scored less or equal to compared to others)

EPSS Date: 2025-05-25 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-3956
https://vuldb.com/?id.306292
https://vuldb.com/?ctiid.306292
https://vuldb.com/?submit.557055
https://github.com/Fc04dB/novel-cloud-vul/blob/main/navol-cloud-vul.md

Timeline