CVE-2024-6506

HIGH

MRW plugin <5.4.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

Information exposure vulnerability in the MRW plugin, in its 5.4.3 version, affecting the "mrw_log" functionality. This vulnerability could allow a remote attacker to obtain other customers' order information and access sensitive information such as name and phone number. This vulnerability also allows an attacker to create or overwrite shipping labels.

Scores

CVSS v3 8.2
EPSS 0.0050
EPSS Percentile 39.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
MRW/MRW plugin 5.4.3
Published Jul 04, 2024
Tracked Since Feb 18, 2026