novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL path. Attackers can trigger unauthorized cache invalidation by accessing the cache/refresh endpoint with the known default password, forcing unnecessary database queries to repopulate the cache.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 14 Sep 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL path. Attackers can trigger unauthorized cache invalidation by accessing the cache/refresh endpoint with the known default password, forcing unnecessary database queries to repopulate the cache. | |
| Title | novel-plus through 5.3.3 Default Cache Management Password in the Front Portal | |
| First Time appeared |
Xxyopen
Xxyopen novel-plus |
|
| Weaknesses | CWE-1392 | |
| CPEs | cpe:2.3:a:xxyopen:novel-plus:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xxyopen
Xxyopen novel-plus |
|
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-14T13:58:43.612Z
Reserved: 2026-09-14T11:34:24.687Z
Link: CVE-2026-90940
No data.
No data.
No data.
OpenCVE Enrichment
No data.
Weaknesses