CVE-2015-2068
NUCLEIMagmi < 0.7.22 - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allow remote attackers to inject arbitrary web script or HTML via the (1) profile parameter to web/magmi.php or (2) QUERY_STRING to web/magmi_import_run.php.
Exploits (1)
Nuclei Templates (1)
Magento Server Mass Importer - Cross-Site Scripting
MEDIUMVERIFIEDby daffainfo
Shodan:
http.component:"Magento" || http.component:"magento"
References (3)
Scores
EPSS
0.0194
EPSS Percentile
83.5%
Details
CWE
CWE-79
Status
published
Products (2)
dweeves/magmi
0 - 0.7.22Packagist
magmi_project/magmi
Published
Feb 24, 2015
Tracked Since
Feb 18, 2026