CVE-2025-61923: PrestaShop Checkout Backoffice directory traversal allows arbitrary file disclosure
Impact Missing validation on input vulnerable to directory traversal.
Patches The problem has been patched in versions:
v4.4.1 for PrestaShop 1.7 (build number: 7.4.4.1) v4.4.1 for PrestaShop 8 (build number: 8.4.4.1) v5.0.5 for PrestaShop 1.7 (build number: 7.5.0.5) v5.0.5 for PrestaShop 8 (build number: 8.5.0.5) v5.0.5 for PrestaShop 9 (build number: 9.5.0.5)
Read the Versioning policy to learn more about the build number.
Credits Léo CUNÉAZ for reportied this issue.
Other sources
PrestaShop Checkout is the PrestaShop official payment module in partnership with PayPal. In versions prior to 4.4.1 and 5.0.5, the backoffice is missing validation on input resulting in a directory traversal and arbitrary file disclosure. The vulnerability is fixed in versions 4.4.1 and 5.0.5. No known workarounds exist.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61923?
CVE-2025-61923 has been classified as a high severity vulnerability due to its potential for arbitrary file disclosure.
How do I fix CVE-2025-61923?
To fix CVE-2025-61923, update PrestaShop Checkout to version 4.4.1 or later for the 4.x branch or version 5.0.5 or later for the 5.x branch.
Which versions of PrestaShop Checkout are affected by CVE-2025-61923?
CVE-2025-61923 affects PrestaShop Checkout versions prior to 4.4.1 and 5.0.5.
What type of vulnerability is CVE-2025-61923?
CVE-2025-61923 is a directory traversal vulnerability that leads to arbitrary file disclosure.
Who is responsible for the PrestaShop Checkout vulnerability CVE-2025-61923?
CVE-2025-61923 affects PrestaShop Checkout, which is the official payment module developed by PrestaShop in partnership with PayPal.