CVE-2026-90940 PUBLISHED

novel-plus through 5.3.3 Default Cache Management Password in the Front Portal

Assigner: VulnCheck
Reserved: 14.09.2026 Published: 14.09.2026 Updated: 14.09.2026

novel-plus through 5.3.3 contains an insecure default cache-management password in the CacheController.refreshCache endpoint that allows anonymous attackers to invalidate portal caches by supplying the hardcoded default value in the URL path. Attackers can trigger unauthorized cache invalidation by accessing the cache/refresh endpoint with the known default password, forcing unnecessary database queries to repopulate the cache.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor 201206030
Product novel-plus
Versions Default: unaffected
  • affected from 0 to 5.3.3 (incl.)

Credits

  • Mingsheng Lin reporter

References

Problem Types

  • Use of Default Credentials CWE