Information exposure vulnerability in the MRW plugin, in its 5.4.3 version, affecting the "mrw_log" functionality. This vulnerability could allow a remote attacker to obtain other customers' order information and access sensitive information such as name and phone number. This vulnerability also allows an attacker to create or overwrite shipping labels.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47590 | Information exposure vulnerability in the MRW plugin, in its 5.4.3 version, affecting the "mrw_log" functionality. This vulnerability could allow a remote attacker to obtain other customers' order information and access sensitive information such as name and phone number. This vulnerability also allows an attacker to create or overwrite shipping labels. |
Fixes
Solution
The vulnerability has been fixed by the MRW team in version 5.5.1.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-01T21:41:03.535Z
Reserved: 2024-07-04T10:08:19.529Z
Link: CVE-2024-6506
Updated: 2024-08-01T21:41:03.535Z
Status : Awaiting Analysis
Published: 2024-07-04T13:15:10.240
Modified: 2024-11-21T09:49:46.537
Link: CVE-2024-6506
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD