PrestaShop Checkout Target PayPal merchant account hijacking from backoffice
Low severity
GitHub Reviewed
Published
Oct 16, 2025
in
PrestaShopCorp/ps_checkout
•
Updated Oct 16, 2025
Package
Affected versions
< 4.4.1
>= 5.0.0, < 5.0.5
Patched versions
4.4.1
5.0.5
Description
Published by the National Vulnerability Database
Oct 16, 2025
Published to the GitHub Advisory Database
Oct 16, 2025
Reviewed
Oct 16, 2025
Last updated
Oct 16, 2025
Impact
Wrong usage of the PHP
array_search()
allows bypass of validation.Patches
The problem has been patched in versions:
Read the Versioning policy to learn more about the build number.
Credits
Léo CUNÉAZ reported this issue.
References