MEDIUM6.1
GHSA-r8vh-cm9f-rc29
Magmi XSS Vulnerability
Quick fix
GHSA-r8vh-cm9f-rc29 — dweeves/magmi: upgrade to the fixed version with the command below.
composer require dweeves/magmi:^0.7.24Details
A Cross-Site Scripting (XSS) was discovered in Magmi 0.7.22. The vulnerability exists due to insufficient filtration of user-supplied data (prefix) passed to the `magmi-git-master/magmi/web/ajax_gettime.php` URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-7391[ADVISORY]
- https://github.com/dweeves/magmi-git/issues/522[WEB]
- https://github.com/dweeves/magmi-git/pull/525[WEB]
- https://github.com/dweeves/magmi-git/commit/a9566b141b58bf40a9dd904a74e6efcc225a28a3[WEB]
- https://web.archive.org/web/20210125191718/http://www.securityfocus.com/bid/97311[WEB]