Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jesús Higueras

#31175of 53,633
8.2Total CVSS
Vulnerabilities · 1
PT-2024-37676
8.2
2024-07-04
Unknown · Mrw Plugin · CVE-2024-6506
**Name of the Vulnerable Software and Affected Versions** MRW plugin version 5.4.3 **Description** The issue is an information exposure vulnerability affecting the "mrw log" functionality. This could allow a remote attacker to obtain other customers' order information and access sensitive information such as name and phone number. The vulnerability also allows an attacker to create or overwrite shipping labels. **Recommendations** For MRW plugin version 5.4.3, consider disabling the "mrw log" functionality until a patch is available. Restrict access to sensitive customer information to minimize the risk of exploitation. Avoid using the affected functionality to prevent potential data breaches. At the moment, there is no information about a newer version that contains a fix for this vulnerability.