Vulnerability Description
Currently, all versions of MAGMI are vulnerable to CSRF due to the lack of CSRF tokens. RCE (via phpcli command) is possible in the event that a CSRF is leveraged against an existing admin session for MAGMI.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Magmi Project | Magmi | All versions |
Related Weaknesses (CWE)
References
- https://www.tenable.com/security/research/tra-2020-51Third Party Advisory
- https://www.tenable.com/security/research/tra-2020-51Third Party Advisory
FAQ
What is CVE-2020-5776?
CVE-2020-5776 is a vulnerability with a CVSS score of 8.8 (HIGH). Currently, all versions of MAGMI are vulnerable to CSRF due to the lack of CSRF tokens. RCE (via phpcli command) is possible in the event that a CSRF is leveraged against an existing admin session for...
How severe is CVE-2020-5776?
CVE-2020-5776 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-5776?
Check the references section above for vendor advisories and patch information. Affected products include: Magmi Project Magmi.