Currently, all versions of MAGMI are vulnerable to CSRF due to the lack of CSRF tokens. RCE (via phpcli command) is possible in the event that a CSRF is leveraged against an existing admin session for MAGMI.
https://www.tenable.com/blog/one-year-later-what-can-we-learn-from-zerologon