ZeroHour

CVE-2025-61923

CVSS 3.1
4.1 medium
EPSS
<1%p56
Published
()
Modified
Description

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the backoffice is missing validation on input resulting in a directory traversal and arbitrary file disclosure. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.

Vendors
prestashop
Products
prestashop checkout
Ecosystems
E-commerce
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.