VDB
Sign up
MEDIUM

GHSA-27v2-398x-f74x

MAGMI cross-site scripting (XSS)

Quick fix

GHSA-27v2-398x-f74x — dweeves/magmi: upgrade to the fixed version with the command below.

composer require dweeves/magmi:^0.7.22

Details

Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allow remote attackers to inject arbitrary web script or HTML via the (1) profile parameter to web/magmi.php or (2) QUERY_STRING to web/magmi_import_run.php.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/dweeves/magmi
Introduced in: 0Fixed in: 0.7.22
Fixcomposer require dweeves/magmi:^0.7.22

References