A CSRF vulnerability still exists in the Magmi plugin for Magento online stores, even though the developers received a report from the researchers who discovered it.
Hackers can use the flaw to execute arbitrary code on servers running Magmi (Magento Mass Importer), by tricking authenticated administrators into clicking a malicious link.

The plugin acts as a Magento database client that can add a large number of products (millions, according to the wiki page) to a catalog or perform updates.
Enguerran Gillier of Tenable's Web Application Security Team analyzed Magmi earlier this year and found two security vulnerabilities that could allow remote code execution. However, only one of the two received an update two days ago.
The issue currently affecting all Magmi versions has been identified as CVE-2020-5776 and stems from the lack of random CSRF tokens that could offer protection against CSRF attacks.
So far, a severity rating is not available for CVE-2020-5776, but Tenable has released proof-of-concept code demonstrating this vulnerability on GitHub , along with instructions on how it works
The second issue discovered in Magmi is an authentication bypass that allows the use of default credentials when the connection to the Magento database fails.
This flaw has now been identified as CVE-2020-5777 and attackers can exploit it by performing a DoS on the Magento database.

Gillier says in a technical overview that DoS is possible when the maximum number of MySQL connections is greater than the maximum allowed by the server for HTTP connections. A PoC for this issue is also available.
According to Tenable, the Magmi vulnerabilities were reported to the developer on June 3. On July 6, the developer acknowledged the glitches, saying they would be addressed.
A new version of the plugin appeared on August 30 with a fix only for the authentication bypass vulnerability, the cybersecurity company said.
Vulnerabilities in previous versions of Magmi have been exploited by the Magecard group to gain unauthorized access to a server hosting an online store. This allowed them to install malicious JavaScript that was able to steal customers' credit card data.
The incident was notable enough, prompting the FBI to release technical details for the e-commerce sector so that organizations can protect themselves from the threat.
Although Magmi is compatible with Magento 1.x which is no longer in active support, the number of plugin downloads in the last six months indicates hundreds of installations.
