QID 994808
Date Published: 2023-08-14
QID 994808: PHP (Composer) Security Update for dweeves/magmi (GHSA-x3gh-95p8-43qv)
Unrestricted file upload vulnerability in magmi/web/magmi.php in the MAGMI (aka Magento Mass Importer) plugin 0.7.17a and earlier for Magento Community Edition (CE) allows remote authenticated users to execute arbitrary code by uploading a ZIP file that contains a PHP file, then accessing the PHP file via a direct request to it in magmi/plugins/.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-x3gh-95p8-43qv for updates and patch information.
Vendor References
- GHSA-x3gh-95p8-43qv -
github.com/advisories/GHSA-x3gh-95p8-43qv
CVEs related to QID 994808
Software Advisories
| Advisory ID | Software | Component | Link |
|---|