Skip to content

MAGMI plugin for Magento Unsafe File Upload

High severity GitHub Reviewed Published May 14, 2022 to the GitHub Advisory Database • Updated Aug 16, 2023

Package

composer dweeves/magmi (Composer)

Affected versions

<= 0.7.17a

Patched versions

None

Description

Unrestricted file upload vulnerability in magmi/web/magmi.php in the MAGMI (aka Magento Mass Importer) plugin 0.7.17a and earlier for Magento Community Edition (CE) allows remote authenticated users to execute arbitrary code by uploading a ZIP file that contains a PHP file, then accessing the PHP file via a direct request to it in magmi/plugins/.

References

Published by the National Vulnerability Database Nov 13, 2014
Published to the GitHub Advisory Database May 14, 2022
Reviewed Aug 7, 2023
Last updated Aug 16, 2023

Severity

High

EPSS score

0.473%
(76th percentile)

Weaknesses

CVE ID

CVE-2014-8770

GHSA ID

GHSA-x3gh-95p8-43qv

Source code

No known source code
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.