疑似Oday
The Ninja Tables plugin for WordPress (versions < 4.1.9) is vulnerable to an unauthenticated arbitrary file download vulnerability. The issue exists due to the improper validation of the 'url' parameter in the 'ninja_table_force_download' AJAX action.
id: wp-ninja-tables-lfi
info:
name: Ninja Tables <4.1.9 - Unauthenticated Arbitrary File Read
a
...