ps_checkout- PrestaShop module vulnerability (CVE-2025-61922)

Moduleps_checkout

Score

9.1 Critical

Date publish

16-10-2025

Versiones afectadas

  • Versions from 1.3.0 up to but not including 7.4.4.1
  • Versions from 7.5.0.1 up to but not including 7.5.0.5
  • Versions from 8.3.1.0 up to but not including 8.4.4.1
  • Versions from 8.5.0.0 up to but not including 8.5.0.5
  • Versions from 9.4.3.1 up to but not including 9.5.0.5

Description

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5.0.5, missing validation on the Express Checkout feature allows silent login, enabling account takeover via email. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.

References

https://github.com/PrestaShopCorp/ps_che...
Patch Vendor Advisory github.com

Metrics

cvssMetricV31
sourcesecurity-advisories@github.com
typeSecondary
version3.1
vectorStringCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
baseScore9.1
baseSeverityCRITICAL
attackVectorNETWORK
attackComplexityLOW
privilegesRequiredNONE
userInteractionNONE
scopeUNCHANGED
confidentialityImpactHIGH
integrityImpactHIGH
availabilityImpactNONE
exploitabilityScore3.9
impactScore5.2
Scroll al inicio