Showing 3 vulnerabilities on this page for magmi

Signals CISA KEV Ransomware Nuclei
magmi_project vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Cross-Site Request Forgery in MAGMI

Currently, all versions of MAGMI are vulnerable to CSRF due to the lack of CSRF tokens. RCE (via phpcli command) is possible in the event that a CSRF is leveraged against an existing admin session for MAGMI.

CWE-352Sep 1, 20201 related artifact
CVSS8.8v3.1EPSS14.7%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

Magmi XSS Vulnerability

A Cross-Site Scripting (XSS) was discovered in 'Magmi 0.7.22'. The vulnerability exists due to insufficient filtration of user-supplied data (prefix) passed to the 'magmi-git-master/magmi/web/ajax_gettime.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

CWE-79Apr 1, 20171 related artifact
CVSS6.1v3.0EPSS8.24%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

MAGMI plugin for Magento Server Directory Traversal

Directory traversal vulnerability in web/ajax_pluginconf.php in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

CWE-22Feb 24, 20151 related artifact
CVSS5.0v2.0EPSS39.4%PoCs1SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX