CVE-2015-2068 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 14% (pctl 96)
Patch early
A public exploit exists.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allow remote attackers to inject arbitrary web script or HTML via the (1) profile parameter to web/magmi.php or (2) QUERY_STRING to web/magmi_import_run.php.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 14.04% — more likely to be exploited than 96% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2015-02-24 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| magmi project | magmi |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Magento Server MAGMI Plugin - Multiple Vulnerabilities | 2015-02-05 |
References
- http://packetstormsecurity.com/files/130250/Magento-Server-MAGMI-Cross-Site-Scripting-Local-File-Inclusion.html
- http://www.exploit-db.com/exploits/35996
- http://www.securityfocus.com/bid/74879
- http://packetstormsecurity.com/files/130250/Magento-Server-MAGMI-Cross-Site-Scripting-Local-File-Inclusion.html
- http://www.exploit-db.com/exploits/35996
- http://www.securityfocus.com/bid/74879
→ the Explorer · watch your stack · NVD