CVE-2020-5776 describes a critical Cross-Site Request Forgery (CSRF) vulnerability in all versions of MAGMI, a Magento plugin. This flaw allows an attacker to leverage an existing administrator session to achieve Remote Code Execution (RCE) via the phpcli command, posing a severe risk to affected systems. With a CVSS score of 8.8 (HIGH) and a FAUCET Risk Score of 99/100, the vulnerability is easily exploitable with low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. While not listed in CISA KEV, exploit intelligence indicates the existence of Nuclei templates for detection, and it has garnered significant community discussion and media coverage, including an article from BleepingComputer.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:magmi_project:magmi:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Cross-Site Request Forgery in MAGMI
May 6, 2021MAGMI Multiple Vulnerabilities
Sep 1, 2020MAGMI Multiple Vulnerabilities
Sep 1, 2020MAGMI Multiple Vulnerabilities
Sep 1, 2020MAGMI Multiple Vulnerabilities
Sep 1, 2020MAGMI Multiple Vulnerabilities
Sep 1, 2020MAGMI Multiple Vulnerabilities
Sep 1, 2020MAGMI Multiple Vulnerabilities
Sep 1, 2020