---
id: CVE-2025-65442
title: >-
  DOM-based Cross-Site Scripting (XSS) vulnerability in 201206030 novel V3.5.0
  allows remote attackers to execute arbitrary JavaScript code or disclose
  sensitive information (e.g., user session cookies) via a crafted "wvstest"
  parameter in…
summary: >-
  DOM-based Cross-Site Scripting (XSS) vulnerability in 201206030 novel V3.5.0
  allows remote attackers to execute arbitrary JavaScript code or disclose
  sensitive information (e.g., user session cookies) via a crafted "wvstest"
  parameter in…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: xxyopen
product: novel
affected:
  - novel = 3.5.0
published: '2025-12-29'
updated: '2026-10-05'
sourceUpdated: '2026-10-05T19:10:00.210'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-65442'
references:
  - url: 'https://github.com/201206030/novel'
    label: cve@mitre.org
  - url: 'https://github.com/201206030/novel-front-web'
    label: cve@mitre.org
  - url: >-
      https://github.com/zero-day348/DOM-based-Cross-Site-Scripting-XSS-Vulnerability-in-novel-V3.5.0-CWE-79-
    label: cve@mitre.org
tags:
  - nvd
  - exploit-available
epss: 0.00355
epssPercentile: 0.26966
exploits:
  github: 1
  githubRepos:
    - >-
      https://github.com/zero-day348/CVE-2025-65442-DOM-based-Cross-Site-Scripting-XSS-Vulnerability-in-novel-V3.5.0-CWE-79-
  checkedAt: '2026-10-05T19:31:35.330Z'
exploitAvailable: true
ingestedAt: '2026-10-05T19:30:59.954Z'
---

## Overview

DOM-based Cross-Site Scripting (XSS) vulnerability in 201206030 novel V3.5.0 allows remote attackers to execute arbitrary JavaScript code or disclose sensitive information (e.g., user session cookies) via a crafted "wvstest" parameter in the URL or malicious script injection into window.localStorage. The vulnerability arises from insufficient validation and encoding of user-controllable data in the book comment module: unfiltered user input is stored in the backend database (book_comment table, commentContent field) and returned via API, then rendered directly into the page DOM via Vue 3's v-html directive without sanitization. Even if modern browsers' built-in XSS filters block pop-up alerts, attackers can use concealed payloads to bypass interception and achieve actual harm.

## Affected

- `novel = 3.5.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
