CVE-2025-61923

EUVD-2025-34789
PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the backoffice is missing validation on input resulting in a directory traversal and arbitrary file disclosure. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.1 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
GitHub_MCNA
4.1 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 19%
Affected Products (NVD)
VendorProductVersion
prestashopprestashop_checkout
𝑥
< 7.4.4.1
prestashopprestashop_checkout
7.5.0.1 ≤
𝑥
< 7.5.0.5
prestashopprestashop_checkout
8.3.1.0 ≤
𝑥
< 8.4.4.1
prestashopprestashop_checkout
8.5.0.0 ≤
𝑥
< 8.5.0.5
prestashopprestashop_checkout
9.4.3.1 ≤
𝑥
< 9.5.0.5
𝑥
= Vulnerable software versions