漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Information exposure vulnerability in the MRW plug-in
Vulnerability Description
Information exposure vulnerability in the MRW plugin, in its 5.4.3 version, affecting the "mrw_log" functionality. This vulnerability could allow a remote attacker to obtain other customers' order information and access sensitive information such as name and phone number. This vulnerability also allows an attacker to create or overwrite shipping labels.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L
Vulnerability Type
信息暴露
Vulnerability Title
MRW plugin 信息泄露漏洞
Vulnerability Description
MRW plugin是西班牙MRW公司的一个物流运输和服务插件。 MRW plugin 5.4.3版本存在信息泄露漏洞。远程攻击者利用该漏洞可以获取其他客户的订单信息并访问姓名和电话号码等敏感信息。
CVSS Information
N/A
Vulnerability Type
N/A