ps_checkout allows unauthorized method invocation through unvalidated parameter
Low severity
GitHub Reviewed
Published
Apr 23, 2026
in
PrestaShopCorp/ps_checkout
•
Updated Apr 30, 2026
Description
Published to the GitHub Advisory Database
Apr 30, 2026
Reviewed
Apr 30, 2026
Last updated
Apr 30, 2026
Impact
Unvalidated parameter can lead to some unauthorized method invocation with very little possibilities.
Patches
The problem has been patched in versions
Read the Versioning policy to learn more about the build numbers.
Credits
PrestaShop thanks PATICEO for reporting the issue.
References