CVE-2025-61924

Published Oct 16, 2025

Last updated 4 months ago

Overview

Description
PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the Target PayPal merchant account hijacking from backoffice due to wrong usage of the PHP array_search(). The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.
Source
security-advisories@github.com
NVD status
Analyzed
Products
prestashop_checkout

Risk scores

CVSS 3.1

Type
Secondary
Base score
3.8
Impact score
2.5
Exploitability score
1.2
Vector string
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N
Severity
LOW

Weaknesses

security-advisories@github.com
CWE-184

Social media

Hype score
Not currently trending

Configurations