PrestaShop Checkout是PrestaShopCorp开源的一个结账支付模块。 PrestaShop Checkout 4.4.1之前版本和5.0.5之前版本存在授权问题漏洞,该漏洞源于Express Checkout功能缺少验证,可能导致通过电子邮件进行账户接管。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PrestaShopCorp | ps_checkout | >= 1.3.0, < 4.4.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/captaincookie34/Vulnerability-Playground-CVE-2025-61922 | POC Details |
| 2 | A simple, educational proof-of-concept script demonstrating the zero-click account takeover vulnerability in the PrestaShop Checkout module (CVE-2025-61922). | https://github.com/g0vguy/CVE-2025-61922-PoC | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-61923 | 4.1 MEDIUM | PrestaShop Checkout Backoffice directory traversal allows arbitrary file disclosure |
| CVE-2025-61924 | 3.8 LOW | PrestaShop Checkout Target PayPal merchant account hijacking from backoffice |
Zaproxy alias impedit expedita quisquam pariatur exercitationem. Nemo rerum eveniet dolores rem quia dignissimos.