Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x3gh-95p8-43qv

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью

Описание

MAGMI plugin for Magento Unsafe File Upload

Unrestricted file upload vulnerability in magmi/web/magmi.php in the MAGMI (aka Magento Mass Importer) plugin 0.7.17a and earlier for Magento Community Edition (CE) allows remote authenticated users to execute arbitrary code by uploading a ZIP file that contains a PHP file, then accessing the PHP file via a direct request to it in magmi/plugins/.

Пакеты

Наименование

dweeves/magmi

composer
Затронутые версииВерсия исправления

<= 0.7.17a

Отсутствует

EPSS

Процентиль: 96%
0.2613
Средний

Дефекты

CWE-94

Связанные уязвимости

nvd
около 11 лет назад

Unrestricted file upload vulnerability in magmi/web/magmi.php in the MAGMI (aka Magento Mass Importer) plugin 0.7.17a and earlier for Magento Community Edition (CE) allows remote authenticated users to execute arbitrary code by uploading a ZIP file that contains a PHP file, then accessing the PHP file via a direct request to it in magmi/plugins/.

EPSS

Процентиль: 96%
0.2613
Средний

Дефекты

CWE-94