Lucene search

K
osvGoogleOSV:GHSA-R8VH-CM9F-RC29
HistoryMay 17, 2022 - 2:51 a.m.

Magmi XSS Vulnerability

2022-05-1702:51:51
Google
osv.dev
6
cross-site scripting
magmi
insufficient filtration
arbitrary code execution
vulnerability

EPSS

0.002

Percentile

57.2%

A Cross-Site Scripting (XSS) was discovered in Magmi 0.7.22. The vulnerability exists due to insufficient filtration of user-supplied data (prefix) passed to the magmi-git-master/magmi/web/ajax_gettime.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

EPSS

0.002

Percentile

57.2%