VDB
Sign up
HIGH8.8

GHSA-cv7m-wc7g-7gfp

Cross-Site Request Forgery in MAGMI

Details

All versions of MAGMI up to and including version 0.7.24 are vulnerable to CSRF due to the lack of CSRF tokens. RCE (via phpcli command) is possible in the event that a CSRF is leveraged against an existing admin session for MAGMI.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/dweeves/magmi
Introduced in: 0

No fixed version published yet for dweeves/magmi (composer). Pin to a known-safe version or switch to an alternative.

References