icon

We found results for “

CVE-2017-7391

Good to know:

icon

Date: March 31, 2017

A Cross-Site Scripting (XSS) was discovered in 'Magmi 0.7.22'. The vulnerability exists due to insufficient filtration of user-supplied data (prefix) passed to the 'magmi-git-master/magmi/web/ajax_gettime.php' URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.

Language: PHP

Severity Score

Severity Score

Weakness Type (CWE)

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-79

Top Fix

icon

Upgrade Version

Upgrade to version lsv/magmi2 - 0.7.19;lsv/magmi2 - 200.7.24;lsv/magmi2 - dev-master;lsv/magmi2 - dev-magento1;macopedia/magmi2 - dev-transaction_logging;macopedia/magmi2 - dev-magento1;macopedia/magmi2 - dev-master;macopedia/magmi2 - 200.7.24;macopedia/magmi2 - dev-fix-missing-attribute-set;dweeves/magmi - 0.7.24;magebinary/magmi - no_fix

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): CHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): NONE

CVSS v2

Base Score:
Access Vector (AV): NETWORK
Access Complexity (AC): MEDIUM
Authentication (AU): NONE
Confidentiality (C): NONE
Integrity (I): PARTIAL
Availability (A): NONE
Additional information:

Do you need more information?

Contact Us