CVE-2024-6506

Information exposure vulnerability in the MRW plugin, in its 5.4.3 version, affecting the "mrw_log" functionality. This vulnerability could allow a remote attacker to obtain other customers' order information and access sensitive information such as name and phone number. This vulnerability also allows an attacker to create or overwrite shipping labels.
CVSS

No CVSS.

Configurations

No configuration.

History

04 Jul 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-04 13:15

Updated : 2024-07-05 12:55


NVD link : CVE-2024-6506

Mitre link : CVE-2024-6506


JSON object : View

Products Affected

No product.

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor