CVE-2025-51586: Medium severity composer/prestashop/prestashop vulnerability
Impact An unauthenticated attacker with access to the back-office URL can manipulate the idemployee and resettoken parameters to enumerate valid back-office employee email addresses.
Impacted parties: Store administrators and employees: their email addresses are exposed. Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts.
Patches PrestaShop 8.2.3
Workarounds You must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/
Other sources
An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-51586?
CVE-2025-51586 has a high severity as it allows unauthenticated attackers to expose valid back-office employee email addresses.
How do I fix CVE-2025-51586?
To fix CVE-2025-51586, upgrade PrestaShop to version 8.2.3 or later.
Who is affected by CVE-2025-51586?
CVE-2025-51586 affects store administrators and employees due to the exposure of their email addresses.
What configurations are vulnerable in CVE-2025-51586?
CVE-2025-51586 is exploitable when the back-office URL is accessible by unauthenticated users.
Can CVE-2025-51586 lead to further attacks?
Yes, CVE-2025-51586 can potentially lead to phishing or identity theft if attacker exploits the exposed email addresses.