| |
Vulnerability CVE-2024-6506
Published: 2024-07-04
| Description: |
Information exposure vulnerability in the MRW plugin, in its 5.4.3 version, affecting the "mrw_log" functionality. This vulnerability could allow a remote attacker to obtain other customers' order information and access sensitive information such as name and phone number. This vulnerability also allows an attacker to create or overwrite shipping labels. |
Type:
CWE-200 (Information Exposure)
References: |
https://www.incibe.es/en/incibe-cert/notices/aviso/information-exposure-vulnerability-mrw-plug
|
|
|
closedb();
?>
Copyright 2026, cxsecurity.com
|
|
|