Description
Information exposure vulnerability in the MRW plugin, in its 5.4.3 version, affecting the "mrw_log" functionality. This vulnerability could allow a remote attacker to obtain other customers' order information and access sensitive information such as name and phone number. This vulnerability also allows an attacker to create or overwrite shipping labels.
No analysis available yet.
Remediation
Vendor Solution
The vulnerability has been fixed by the MRW team in version 5.5.1.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47590 | Information exposure vulnerability in the MRW plugin, in its 5.4.3 version, affecting the "mrw_log" functionality. This vulnerability could allow a remote attacker to obtain other customers' order information and access sensitive information such as name and phone number. This vulnerability also allows an attacker to create or overwrite shipping labels. |
References
History
No history.
Subscriptions
No data.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-01T21:41:03.535Z
Reserved: 2024-07-04T10:08:19.529Z
Link: CVE-2024-6506
Updated: 2024-08-01T21:41:03.535Z
Status : Deferred
Published: 2024-07-04T13:15:10.240
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-6506
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD