VulnerabilityModified
CVE-2020-5776
Currently, all versions of MAGMI are vulnerable to CSRF due to the lack of CSRF tokens.
HIGH 8.8EPSS 14.7%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 14.7%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
Currently, all versions of MAGMI are vulnerable to CSRF due to the lack of CSRF tokens. RCE (via phpcli command) is possible in the event that a CSRF is leveraged against an existing admin session for MAGMI.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 14.72% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- magmi project/magmi
- Source
- vulnreport@tenable.com
References
- https://www.tenable.com/security/research/tra-2020-51Third Party Advisory
- https://www.tenable.com/security/research/tra-2020-51Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.