CVE-2025-6533 | xxyopen/201206030 novel-plus up to 5.1.3 CATCHA LoginController.java ajaxLogin authentication replay (EUVD-2025-18961)
A vulnerability, which was classified as critical, has been found in xxyopen/201206030 novel-plus up to 5.1.3. Affected by this issue is the function ajaxLogin of the file novel-admin/src/main/java/com/java2nb/system/controller/LoginController.java of the component CATCHA Handler. The manipulation leads to authentication bypass by capture-replay.
This vulnerability is handled as CVE-2025-6533. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.