CVE-2025-25692: Command Injection
Published Jul 30, 2025
·Updated
A PHAR deserialization vulnerability in the getHeaders function of PrestaShop v8.2.0 allows attackers to execute arbitrary code via a crafted POST request.
Affected Software
2 affected components
Prestashop PrestaShop
Prestashop PrestaShop=8.2.0
Event History
Jul 30, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-25692?
CVE-2025-25692 is considered a high severity vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2025-25692?
To mitigate CVE-2025-25692, upgrade PrestaShop to version 8.2.1 or later, where this vulnerability has been addressed.
3
What is the impact of CVE-2025-25692?
The impact of CVE-2025-25692 allows attackers to execute arbitrary code on affected systems via crafted POST requests.
4
Which version of PrestaShop is affected by CVE-2025-25692?
CVE-2025-25692 affects PrestaShop version 8.2.0.
5
What kind of vulnerability is CVE-2025-25692?
CVE-2025-25692 is a PHAR deserialization vulnerability.