Magento plugin Magmi vulnerable to hijacking admin sessions

CyberPanther

Level 7
Thread author
Verified
Well-known
Oct 1, 2019
298
1,902
569
Saudi Arabia
A cross-site request forgery (CSRF) vulnerability continues to be present in the Magmi plugin for Magento online stores, despite developers receiving a report from researchers that discovered it.

Hackers can use the flaw to execute arbitrary code on servers running Magmi (Magento Mass Importer) by tricking authenticated administrators into clicking a malicious link.

The plugin works as a Magento database client that can add a large number of products (millions, according to its wiki page) to a catalog or update it.