Le forme Ninja plug prima 3.3.14.1 per WordPress permette l’iniezione CSV. |
https://www.exploit-db.com/exploits/45234/ https://packetstormsecurity.com/files/148993/WordPress-Ninja-Forms-3.3.13-CSV-Injection.html https://wordpress.org/plugins/ninja-forms/#developers https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-16308 |
Vulnerabilità: CVE-2018-16308
