Arbitrary File Read vulnerability in novel-plus 4.3.0 and before allows a remote attacker to obtain sensitive information via a crafted GET request using the filePath parameter.
The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.