CVE Vulnerabilities

CVE-2025-61922

Improper Authentication

Published: Oct 16, 2025 | Modified: Dec 29, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. Starting in version 1.3.0 and prior to versions 4.4.1 and 5.0.5, missing validation on the Express Checkout feature allows silent login, enabling account takeover via email. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Prestashop_checkoutPrestashop1.3.0 (including)7.4.4.1 (excluding)
Prestashop_checkoutPrestashop7.5.0.1 (including)7.5.0.5 (excluding)
Prestashop_checkoutPrestashop8.3.1.0 (including)8.4.4.1 (excluding)
Prestashop_checkoutPrestashop8.5.0.0 (including)8.5.0.5 (excluding)
Prestashop_checkoutPrestashop9.4.3.1 (including)9.5.0.5 (excluding)

Potential Mitigations

References