Magmi 0.7.22 contains a cross-site scripting vulnerability due to insufficient filtration of user-supplied data (prefix) passed to the magmi-git-master/magmi/web/ajax_gettime.php URL.
id: CVE-2017-7391
info:
name: Magmi 0.7.22 - Cross-Site Scripting
author: pikpikcu
severity:
...