vendor:
MAGMI Plugin
by:
SECUPENT
8.8
CVSS
HIGH
Local File Inclusion and Cross Site Scripting
94
CWE
Product Name: MAGMI Plugin
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2015
Magento Server MAGMI Plugin Local File Inclusion And Cross Site Scripting
The vulnerability exists due to insufficient sanitization of user-supplied input in 'file' and 'profile' parameters of 'ajax_pluginconf.php' and 'magmi.php' and 'magmi_import_run.php' scripts. A remote attacker can execute arbitrary HTML and script code in a browser in the context of the vulnerable website. Successful exploitation of this vulnerability may allow an attacker to steal cookie-based authentication credentials and launch other attacks.
Mitigation:
Update to the latest version of Magento Server MAGMI Plugin.