ZeroHour

CVE-2020-5776

CVSS 3.1
8.8 high
EPSS
15%p96
Published
()
Modified
Description

Currently, all versions of MAGMI are vulnerable to CSRF due to the lack of CSRF tokens. RCE (via phpcli command) is possible in the event that a CSRF is leveraged against an existing admin session for MAGMI.

Vendors
magmi project
Products
magmi
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news