CVE-2025-61922
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-16

Last updated on: 2025-12-29

Assigner: GitHub, Inc.

Description
PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5.0.5, missing validation on the Express Checkout feature allows silent login, enabling account takeover via email. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-16
Last Modified
2025-12-29
Generated
2026-05-07
AI Q&A
2025-10-16
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 5 associated CPEs
Vendor Product Version / Range
prestashop prestashop_checkout From 1.3.0 (inc) to 7.4.4.1 (exc)
prestashop prestashop_checkout From 7.5.0.1 (inc) to 7.5.0.5 (exc)
prestashop prestashop_checkout From 8.3.1.0 (inc) to 8.4.4.1 (exc)
prestashop prestashop_checkout From 8.5.0.0 (inc) to 8.5.0.5 (exc)
prestashop prestashop_checkout From 9.4.3.1 (inc) to 9.5.0.5 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in the PrestaShop Checkout payment module (versions prior to 4.4.1 and 5.0.5). It is caused by missing validation on the Express Checkout feature, which allows an attacker to perform a silent login using just an email address. This enables the attacker to take over user accounts without their knowledge.


How can this vulnerability impact me? :

The vulnerability can lead to account takeover, allowing attackers to gain unauthorized access to user accounts. This can result in unauthorized transactions, theft of personal and payment information, and potential financial loss or fraud.


What immediate steps should I take to mitigate this vulnerability?

Upgrade PrestaShop Checkout to version 4.4.1 or 5.0.5 or later, as these versions contain the fix for the vulnerability. No known workarounds exist, so updating is the only immediate mitigation.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart