PT-2025-42515 · Prestashop · Prestashop Checkout

Inem0O

·

Published

2025-10-16

·

Updated

2026-01-03

·

CVE-2025-61923

CVSS v3.1

4.1

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions PrestaShop Checkout versions prior to 4.4.1 and 5.0.5
Description The PrestaShop Checkout module is susceptible to a directory traversal and arbitrary file disclosure due to missing input validation in the backoffice. This allows unauthorized access to files.
Recommendations Update to PrestaShop Checkout version 4.4.1 for PrestaShop 1.7. Update to PrestaShop Checkout version 4.4.1 for PrestaShop 8. Update to PrestaShop Checkout version 5.0.5 for PrestaShop 1.7. Update to PrestaShop Checkout version 5.0.5 for PrestaShop 8. Update to PrestaShop Checkout version 5.0.5 for PrestaShop 9.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-61923
GHSA-FPXP-PFQM-X54W

Affected Products

Prestashop Checkout