CVE-2025-61924
LOWDescription
PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the Target PayPal merchant account hijacking from backoffice due to wrong usage of the PHP array_search(). The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.
Is your site exposed to CVE-2025-61924?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| prestashop | prestashop_checkout |
| prestashop | prestashop_checkout |
| prestashop | prestashop_checkout |
| prestashop | prestashop_checkout |
| prestashop | prestashop_checkout |
References
Frequently Asked Questions
What is CVE-2025-61924? +
How severe is CVE-2025-61924? +
What products are affected by CVE-2025-61924? +
How do I check if I'm vulnerable to CVE-2025-61924? +
Related Vulnerabilities
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior …
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the …
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise …
Picklescan before 0.0.25 fails to detect unsafe global functions in the Numpy library, allowing attackers to bypass static analysis and …
Wasmtime is a fast and secure runtime for WebAssembly. Wasmtime's filesystem sandbox implementation on Windows blocks access to special device …
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist …