Skip to content

Commit dde71de

Browse files
committed
upgrade version, fix security issue
1 parent 18bd9ec commit dde71de

File tree

4 files changed

+11
-3
lines changed

4 files changed

+11
-3
lines changed

magmi/ReleaseNotes.txt

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,9 @@
1+
------------------------------------------------
2+
- RELEASE NOTES FOR MAGMI 0.7.24 -
3+
-------------------------------------------------
4+
5+
IMPORTANT Security fix, remove default login magmi:magmi since it can be exploited.
6+
17
------------------------------------------------
28
- RELEASE NOTES FOR MAGMI 0.7.23 -
39
-------------------------------------------------

magmi/inc/magmi_auth.php

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,9 @@ public function __construct($user,$pass){
3232

3333

3434
public function authenticate(){
35-
if (!$this->_hasDB) return ($this->user == 'magmi' && $this->pass == 'magmi');
35+
if(!$this->_hasDB) {
36+
die("Please create magmi.ini file in magmi/conf directory , by copying & editing magmi.ini.default file and filling appropriate values");
37+
}
3638
$tn=$this->tablename('admin_user');
3739
$result = $this->select("SELECT * FROM $tn WHERE username = ?",array($this->user))->fetch(PDO::FETCH_ASSOC);
3840
return $this->validatePass($result['password'],$this->pass);

magmi/inc/magmi_version.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
<?php
22
class Magmi_Version
33
{
4-
public static $version="0.7.23-git";
4+
public static $version="0.7.24-git";
55
}

magmi/web/security.php

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -39,7 +39,7 @@ function authenticate($username="",$password=""){
3939
if (!isset($_SERVER['PHP_AUTH_USER'])) {
4040
header('WWW-Authenticate:Basic realm="Magmi"');
4141
header('HTTP/1.0 401 Unauthorized');
42-
echo 'You must be logged in to use Magmi';
42+
echo 'You must be logged into magento admin to use Magmi';
4343
die();
4444
} else {
4545
if (!authenticate($_SERVER['PHP_AUTH_USER'],$_SERVER['PHP_AUTH_PW'])){

0 commit comments

Comments
 (0)