{"id":"GHSA-x3gh-95p8-43qv","summary":"MAGMI plugin for Magento Unsafe File Upload","details":"Unrestricted file upload vulnerability in `magmi/web/magmi.php` in the MAGMI (aka Magento Mass Importer) plugin 0.7.17a and earlier for Magento Community Edition (CE) allows remote authenticated users to execute arbitrary code by uploading a ZIP file that contains a PHP file, then accessing the PHP file via a direct request to it in `magmi/plugins/`.","aliases":["CVE-2014-8770"],"modified":"2023-11-08T03:57:46.088173Z","published":"2022-05-14T00:56:27Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-08-07T20:02:36Z","nvd_published_at":"2014-11-13T21:32:00Z","cwe_ids":["CWE-94"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2014-8770"},{"type":"WEB","url":"https://sourceforge.net/projects/magmi/files/magmi-0.7/plugins/packages"},{"type":"WEB","url":"http://www.exploit-db.com/exploits/35052"}],"affected":[{"package":{"name":"dweeves/magmi","ecosystem":"Packagist","purl":"pkg:composer/dweeves/magmi"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.7.17a"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-x3gh-95p8-43qv/GHSA-x3gh-95p8-43qv.json"}}],"schema_version":"1.9.0"}