OSV 1.4.0 · github-reviewed · 修改于 2021-05-06 03:10
发布时间
2021-05-07 02:54
GitHub 审查时间
2021-05-06 03:10
NVD 发布时间
2020-09-02 05:15
源文件
advisories/github-reviewed/2021/05/GHSA-cv7m-wc7g-7gfp/GHSA-cv7m-wc7g-7gfp.json
All versions of MAGMI up to and including version 0.7.24 are vulnerable to CSRF due to the lack of CSRF tokens. RCE (via phpcli command) is possible in the event that a CSRF is leveraged against an existing admin session for MAGMI.