PT-2024-37676 · Unknown · Mrw Plugin
Jesús Higueras
·
Published
2024-07-04
·
Updated
2024-07-08
·
CVE-2024-6506
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
MRW plugin version 5.4.3
Description
The issue is an information exposure vulnerability affecting the "mrw log" functionality. This could allow a remote attacker to obtain other customers' order information and access sensitive information such as name and phone number. The vulnerability also allows an attacker to create or overwrite shipping labels.
Recommendations
For MRW plugin version 5.4.3, consider disabling the "mrw log" functionality until a patch is available. Restrict access to sensitive customer information to minimize the risk of exploitation. Avoid using the affected functionality to prevent potential data breaches. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mrw Plugin