Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-6506

Опубликовано: 04 июл. 2024
Источник: nvd
CVSS3: 8.2
EPSS Низкий

Описание

Information exposure vulnerability in the MRW plugin, in its 5.4.3 version, affecting the "mrw_log" functionality. This vulnerability could allow a remote attacker to obtain other customers' order information and access sensitive information such as name and phone number. This vulnerability also allows an attacker to create or overwrite shipping labels.

EPSS

Процентиль: 65%
0.0048
Низкий

8.2 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 8.2
github
больше 1 года назад

Information exposure vulnerability in the MRW plugin, in its 5.4.3 version, affecting the "mrw_log" functionality. This vulnerability could allow a remote attacker to obtain other customers' order information and access sensitive information such as name and phone number. This vulnerability also allows an attacker to create or overwrite shipping labels.

EPSS

Процентиль: 65%
0.0048
Низкий

8.2 High

CVSS3

Дефекты

CWE-200