CVE-2025-61924
LOWDescription
PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the Target PayPal merchant account hijacking from backoffice due to wrong usage of the PHP array_search(). The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.
Is your site exposed to CVE-2025-61924?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| prestashop | prestashop_checkout |
| prestashop | prestashop_checkout |
| prestashop | prestashop_checkout |
| prestashop | prestashop_checkout |
| prestashop | prestashop_checkout |
References
Frequently Asked Questions
What is CVE-2025-61924? +
How severe is CVE-2025-61924? +
What products are affected by CVE-2025-61924? +
How do I check if I'm vulnerable to CVE-2025-61924? +
Related Vulnerabilities
Picklescan before 0.0.25 fails to detect unsafe global functions in the Numpy library, allowing attackers to bypass static analysis and …
AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallowed Inputs” by …
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior …
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise …
A Code Injection vulnerability in adk web in Google Cloud Agent Development Kit (ADK) for Python versions 2.0.0 through 2.6.0 …
Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions before 3.12.4 and versions 4.0.0 through 4.0.3, …