CVE 3.8 LOW

PrestaShop Checkout Target PayPal merchant account hijacking from backoffice_CVE-2025-61924

3.8 / 10
LOW
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N

Description

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the Target PayPal merchant account hijacking from backoffice due to wrong usage of the PHP array_search(). The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.

Basic Information

ID CVE-2025-61924
Source GitHub_M
Published Oct 16, 2025 at 17:33

Affected Product

Vendor PrestaShopCorp
Product ps_checkout
Version < 4.4.1
Affected Versions PrestaShopCorp ps_checkout < 4.4.1
PrestaShopCorp ps_checkout >= 5.0.0, < 5.0.5

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.