GHSA-g475-pch5-6wvv · Severity: critical · Ecosystem: composer — Authentication bypass in MAGMI
MAGMI versions prior to 0.7.24 are vulnerable to a remote authentication bypass due to allowing default credentials in the event there is a database connection failure. A remote attacker can trigger this connection failure if the Mysql setting max_connections (default 151) is lower than Apache (or another web server) setting MaxRequestWorkers (formerly MaxClients) (default 256). This can be done by sending at least 151 simultaneous requests to the Magento website to trigger a "Too many connections" error, then use default magmi:magmi basic authentication to remotely bypass authentication.
Conclusion & alert: CVE-2020-5777 is rated High Risk (72.3/100): CVSS Critical severity, with high exploitation likelihood (EPSS 89.70%, 100th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-06 | 91.47% | 89.70% | -1.77% |
| 2 | 2025-11-21 | 80.57% | 91.47% | +10.90% |
| 3 | 2025-11-18 | — | 80.57% | — |
Full EPSS history (27 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
GHSA-g475-pch5-6wvv · Severity: critical · Ecosystem: composer — Authentication bypass in MAGMI
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| magmi_project | magmi | < 0.7.24 | cpe:2.3:a:magmi_project:magmi:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://www.tenable.com/security/research/tra-2020-51 | Third Party Advisory |