MEDIUM
GHSA-27v2-398x-f74x
MAGMI cross-site scripting (XSS)
Quick fix
GHSA-27v2-398x-f74x — dweeves/magmi: upgrade to the fixed version with the command below.
composer require dweeves/magmi:^0.7.22Details
Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allow remote attackers to inject arbitrary web script or HTML via the (1) profile parameter to web/magmi.php or (2) QUERY_STRING to web/magmi_import_run.php.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2015-2068[ADVISORY]
- https://github.com/dweeves/magmi-git[PACKAGE]
- http://packetstormsecurity.com/files/130250/Magento-Server-MAGMI-Cross-Site-Scripting-Local-File-Inclusion.html[WEB]
- http://www.exploit-db.com/exploits/35996[WEB]
- http://www.securityfocus.com/bid/74879[WEB]