CVE-2015-2068
43Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 14%
from disclosure to weapon0 days
Published on NVDFeb 24
1st PoCFeb 5
exploitation probability
14%top 4% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allow remote attackers to inject arbitrary web script or HTML via the (1) profile parameter to web/magmi.php or (2) QUERY_STRING to web/magmi_import_run.php.
Affected products
n/a · n/apublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/35996unverifiedcve_referencepacketstormsecurity.com/files/130250/Magento-Server-MAGMI-Cross-Site-Scripting-Local-File-Inclusion.htmlunverifiedcve_referencewww.exploit-db.com/exploits/35996unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.