CVE-2025-61923
16.10.2025, 18:15
PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the backoffice is missing validation on input resulting in a directory traversal and arbitrary file disclosure. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.
| Vendor | Product | Version |
|---|---|---|
| prestashop | prestashop_checkout | 𝑥 < 7.4.4.1 |
| prestashop | prestashop_checkout | 7.5.0.1 ≤ 𝑥 < 7.5.0.5 |
| prestashop | prestashop_checkout | 8.3.1.0 ≤ 𝑥 < 8.4.4.1 |
| prestashop | prestashop_checkout | 8.5.0.0 ≤ 𝑥 < 8.5.0.5 |
| prestashop | prestashop_checkout | 9.4.3.1 ≤ 𝑥 < 9.5.0.5 |
𝑥
= Vulnerable software versions