Executive brief
novel-plus is an open-source novel reading CMS system with subscription and VIP features. An authenticated attacker with backend admin access can bypass permission checks in the book download endpoint to export complete books including paid chapters without triggering VIP or purchase verification, undermining the subscription revenue model and exposing paid content.
Technical details
The BookController download endpoint in novel-plus through version 5.3.3 fails to enforce proper authorization checks on book content retrieval. An authenticated backend admin can supply a bookId and bookName parameter to retrieve all chapter content, including premium/paid chapters, bypassing the VIP status verification and purchase authorization checks that are enforced elsewhere in the application. The vulnerability requires valid backend authentication and allows complete book text export. A patch or update beyond version 5.3.3 is needed to add proper permission validation in the download endpoint.
Affected products
- novel-plus novel-plus through 5.3.3
Timeline
- 2026-09-14: disclosed