Magmi 0.7.22 contains a cross-site scripting vulnerability due to insufficient filtration of user-supplied data (prefix) passed to the magmi-git-master/magmi/web/ajax_gettime.php URL.
View the template here CVE-2017-7391.yaml
References:
https://github.com/dweeves/magmi-git/pull/525