PT-2026-6549 · Unknown · Prestashop

Lam Yiu Tung

·

Published

2026-02-03

·

Updated

2026-02-11

·

CVE-2026-25597

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions PrestaShop versions prior to 8.2.4 PrestaShop versions prior to 9.0.3
Description PrestaShop contains a time-based user enumeration issue in its user authentication functionality. An attacker can determine if a customer account exists by observing response times. The vulnerable functionality does not involve any API endpoints or specific parameters. The authenticate() function is affected.
Recommendations Update to PrestaShop version 8.2.4 or later. Update to PrestaShop version 9.0.3 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BIT-PRESTASHOP-2026-25597
CVE-2026-25597
GHSA-67V7-3G49-MXH2

Affected Products

Prestashop