Magento Server Mass Importer plugin contains multiple cross-site scripting vulnerabilities which allow remote attackers to inject arbitrary web script or HTML via the (1) profile parameter to web/magmi.php or (2) QUERY_STRING to web/magmi_import_run.php.
id: CVE-2015-2068
info:
name: Magento Server Mass Importer - Cross-Site Scripting
author: daffa
...