Description
Currently, all versions of MAGMI are vulnerable to CSRF due to the lack of CSRF tokens. RCE (via phpcli command) is possible in the event that a CSRF is leveraged against an existing admin session for MAGMI.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-cv7m-wc7g-7gfp | Cross-Site Request Forgery in MAGMI |
References
| Link | Providers |
|---|---|
| https://www.tenable.com/security/research/tra-2020-51 |
|
History
No history.
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2024-08-04T08:39:25.860Z
Reserved: 2020-01-06T00:00:00.000Z
Link: CVE-2020-5776
No data.
Status : Modified
Published: 2020-09-01T21:15:12.583
Modified: 2024-11-21T05:34:34.857
Link: CVE-2020-5776
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA