Record summary

CVE-2017-7391 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

A Cross-Site Scripting (XSS) was discovered in 'Magmi 0.7.22'. The vulnerability exists due to insufficient filtration of user-supplied data (prefix) passed to the 'magmi-git-master/magmi/web/ajax_gettime.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · May 18, 2020 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
GitHub AdvisoryBefore 0.7.24 · Fixed in 0.7.24affected

Nuclei templates

1
ProjectDiscoveryMEDIUMMagmi 0.7.22 - Cross-Site ScriptingCVSS 6.1

Magmi 0.7.22 contains a cross-site scripting vulnerability due to insufficient filtration of user-supplied data (prefix) passed to the magmi-git-master/magmi/web/ajax_gettime.php URL.

Impact

Successful exploitation of this vulnerability could allow an attacker to execute arbitrary JavaScript code in the context of the victim's browser, leading to session hijacking, defacement, or theft of sensitive information.

Remediation

Upgrade to a patched version of Magmi or apply the necessary security patches to mitigate the XSS vulnerability.

WeaknessesCWE-79
Authorspikpikcu
Template tagscve2017cvemagmixssmagmi_projectvkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:magmi_project:magmi:0.7.22:*:*:*:*:*:*:*
Shodan: http.component:"magento"

Source: ProjectDiscovery

References

6