Ninja Tables <4.1.9 - Unauthenticated Arbitrary File Read
The Ninja Tables plugin for WordPress (versions < 4.1.9) is vulnerable to an unauthenticated arbitrary file download vulnerability. The issue exists due to the improper validation of the 'url' parameter in the 'ninja_table_force_download' AJAX action.
ninja-tablesPoC 已收录
CVSS—