#VU46282 Improper Authentication in Magmi - CVE-2020-5777
Published: September 4, 2020
Magmi
Sebastien Bracquemont
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to the affected software allows default magmi:magmi credentials to be used in the event a database connection fails. A remote attacker can authenticate with default credentials and execute arbitrary commands on the server by uploading a php webshell.