PoC Index

CVE-2015-2068

MEDIUM 4.3EPSS 14.0%

Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allow remote attackers to inject arbitrary web script or HTML via the (1) profile parameter to web/magmi.php or (2) QUERY_STRING to web/magmi_import_run.php.

CVSS v2.0
4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS
14.04% chance of exploitation in the next 30 days, 96th percentile
Nuclei
medium · CWE-79
Published
2015-02-24
Updated
2024-08-06

Proof-of-concept exploits (2)

Nuclei templates (1)

ExploitDB entries (1)

References

Related