CVE-2015-2068
MAGMI cross-site scripting (XSS)
EPSS 14.0%
Description
Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allow remote attackers to inject arbitrary web script or HTML via the (1) profile parameter to web/magmi.php or (2) QUERY_STRING to web/magmi_import_run.php.
How to fix CVE-2015-2068
To remediate CVE-2015-2068, upgrade the affected package to a fixed version below.
- Packagist/dweeves/magmi—upgrade to 0.7.22 or later
Is CVE-2015-2068 being exploited?
Moderate — EPSS is 14.0%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 0.7.22