ZeroHour

CVE-2025-61924

CVSS 3.1
3.8 low
EPSS
<1%p17
Published
()
Modified
Description

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the Target PayPal merchant account hijacking from backoffice due to wrong usage of the PHP array_search(). The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.

Vendors
prestashop
Products
prestashop checkout
Ecosystems
E-commerce
Weakness
CWE-184
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.