CVE-2015-2068

NUCLEI

Magmi < 0.7.22 - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allow remote attackers to inject arbitrary web script or HTML via the (1) profile parameter to web/magmi.php or (2) QUERY_STRING to web/magmi_import_run.php.

Exploits (1)

exploitdb WORKING POC
by SECUPENT · textwebappsphp
https://www.exploit-db.com/exploits/35996

Nuclei Templates (1)

Magento Server Mass Importer - Cross-Site Scripting
MEDIUMVERIFIEDby daffainfo
Shodan: http.component:"Magento" || http.component:"magento"

Scores

EPSS 0.0194
EPSS Percentile 83.5%

Details

CWE
CWE-79
Status published
Products (2)
dweeves/magmi 0 - 0.7.22Packagist
magmi_project/magmi
Published Feb 24, 2015
Tracked Since Feb 18, 2026