Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4308
HistoryMay 26, 2017 - 8:35 a.m.

Cross-Site Scripting (XSS) And Arbitrary Code Execution

2017-05-2608:35:25
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

EPSS

0.002

Percentile

57.2%

dweeves/magmi-git is vulnerable to cross-site scripting (XSS) and arbitrary code execution attacks. The attacks are possible because user-supplied data (prefix) are being input to the magmi-git-master/magmi/web/ajax_gettime.php URL without enough filtering.

EPSS

0.002

Percentile

57.2%