Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-54hq-mf6h-48xh

Опубликовано: 16 окт. 2025
Источник: github
Github: Прошло ревью
CVSS3: 9.1

Описание

PrestaShop Checkout allows customer account takeover via email

Impact

Missing validation on Express Checkout feature allows silent log-in

Affected versions

The issue was introduced in PrestaShop Checkout 1.3.0 .

All versions above 1.3.0 are vulnerable except of course the patch versions published on 16/10/2025: 7.4.4.1, 8.4.4.1, 7.5.0.5, 8.5.0.5, 9.5.0.5

Patches

The problem has been patched in versions

  • v4.4.1 for PrestaShop 1.7 (build number: 7.4.4.1)
  • v4.4.1 for PrestaShop 8 (build number: 8.4.4.1)
  • v5.0.5 for PrestaShop 1.7 (build number: 7.5.0.5)
  • v5.0.5 for PrestaShop 8 (build number: 8.5.0.5)
  • v5.0.5 for PrestaShop 9 (build number: 9.5.0.5)

Read our Versioning policy to learn more about our build numbers and versions of PrestaShop Checkout

Credits

We would like to thank Léo CUNÉAZ for reporting the issue.

Пакеты

Наименование

prestashop/ps_checkout

composer
Затронутые версииВерсия исправления

>= 1.3.0, < 4.4.1

4.4.1

Наименование

prestashop/ps_checkout

composer
Затронутые версииВерсия исправления

>= 5.0.0, < 5.0.5

5.0.5

EPSS

Процентиль: 14%
0.00044
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

CVSS3: 9.1
nvd
4 месяца назад

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5.0.5, missing validation on the Express Checkout feature allows silent login, enabling account takeover via email. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.

EPSS

Процентиль: 14%
0.00044
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-287