-
CVSS Score
-The vulnerability description identifies two injection points (profile parameter in web/magmi.php and QUERY_STRING in web/magmi_import_run.php) but does not provide specific function names or code snippets. While the attack vectors are clear, the lack of available patch details, commit diffs, or source code analysis makes it impossible to confidently identify the exact vulnerable functions responsible for handling these parameters. The XSS vulnerability likely exists in the parameter handling logic of these files, but without concrete code evidence, we cannot specify function names with high confidence.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| dweeves/magmi | composer | < 0.7.22 | 0.7.22 |