CVE-2015-2067
MAGMI plugin for Magento Server Directory Traversal
EPSS 39.4%
Description
Directory traversal vulnerability in web/ajax_pluginconf.php in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
How to fix CVE-2015-2067
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Packagist/dweeves/magmi—no fix listed
Is CVE-2015-2067 being exploited?
Moderate — EPSS is 39.4%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, <= 0.7.21