What the vulnerability does
01Description
Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
What the vulnerability does
Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.
Explanation of Vulnerability in Simple Terms
Ninja Tables versions up to 5.2.10 expose sensitive information through improper access controls. An unauthenticated attacker can read data that should be restricted, such as table contents or configuration details. The vulnerability requires no user interaction and can be exploited over the network. Update to a version newer than 5.2.10 to resolve this issue.
What an attacker can do
Read sensitive data from tables or plugin configuration without authentication.
Potential impact on your site
Confidential table data and plugin settings may be exposed to the public internet.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities