Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Information exposure vulnerability in the MRW plug-in
Vulnerability Description
Information exposure vulnerability in the MRW plugin, in its 5.4.3 version, affecting the "mrw_log" functionality. This vulnerability could allow a remote attacker to obtain other customers' order information and access sensitive information such as name and phone number. This vulnerability also allows an attacker to create or overwrite shipping labels.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Vulnerability Type
信息暴露
Vulnerability Title
MRW plugin 信息泄露漏洞
Vulnerability Description
MRW plugin是西班牙MRW公司的一个物流运输和服务插件。 MRW plugin 5.4.3版本存在信息泄露漏洞。远程攻击者利用该漏洞可以获取其他客户的订单信息并访问姓名和电话号码等敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A