prestashop.md (3409B)
1 --- 2 title: "PrestaShop" 3 section: "Network Services" 4 sectionSlug: "network-services-pentesting" 5 sourcePath: "src/network-services-pentesting/pentesting-web/prestashop.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/prestashop.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # PrestaShop 14 15 ## From XSS to RCE 16 17 PrestaXSRF automates cross-site request forgery chains that turn an existing back-office XSS into higher-impact actions on PrestaShop 1.7.x and 8.x. Its `PSUploadModule()` workflow causes an authenticated administrator's browser to upload a malicious module, resulting in persistent code execution.<sup>[[3]](#references)[[4]](#references)</sup> 18 19 ## ps_checkout ExpressCheckout silent login account takeover (CVE-2025-61922) 20 21 Missing identity validation in the `ps_checkout` Express Checkout flow allows an unauthenticated attacker to switch the current storefront session to a customer account by supplying that customer's email address. Affected releases are `>= 1.3.0, < 4.4.1` and `>= 5.0.0, < 5.0.5`; versions 4.4.1 and 5.0.5 contain the fix.<sup>[[1]](#references)[[2]](#references)</sup> 22 23 - **Unauthenticated endpoint:** `POST /module/ps_checkout/ExpressCheckout`. 24 - **Flow:** `ExpressCheckout.php` accepts attacker JSON, only checks `orderID`, builds `ExpressCheckoutRequest` and calls `ExpressCheckoutAction::execute()`. 25 - **Authentication bug:** In vulnerable versions, `ExpressCheckoutAction` calls `CustomerAuthenticationAction::execute()` when no customer is logged in. The vulnerable flow effectively performs `customerExists(<payer_email>)` followed by `context->updateCustomer(new Customer($id))`, updating the customer context without verifying a password or token. 26 - **Attacker-controlled email field:** `order.payer.email_address` inside the JSON payload is read by `ExpressCheckoutRequest::getPayerEmail()`. 27 28 ### Exploitation steps 29 30 1. Collect any registered customer email (admin is separate and not affected by this flow). 31 2. Send an unauthenticated POST to the controller with `orderID` plus the victim email in `order.payer.email_address`. 32 3. Capture the returned session cookies. In the demonstrated flow, the customer context is updated even when the endpoint later returns `500`, allowing access to the victim's storefront account. Depending on the data and actions exposed by that shop, this can disclose the customer's personally identifiable information or permit purchases through payment methods already available to the account.<sup>[[2]](#references)</sup> 33 34 ```http 35 POST /module/ps_checkout/ExpressCheckout HTTP/1.1 36 Host: <target> 37 Content-Type: application/json 38 Content-Length: 72 39 40 {"orderID":"1","order":{"payer":{"email_address":"victim@example.com"}}} 41 ``` 42 43 ## References 44 45 - [1] [GitHub Security Advisory GHSA-54hq-mf6h-48xh: PrestaShop Checkout account takeover](https://github.com/PrestaShopCorp/ps_checkout/security/advisories/GHSA-54hq-mf6h-48xh) 46 - [2] [Ananda Dhakal: CVE-2025-61922 technical analysis](https://dhakal-ananda.com.np/blogs/cve-2025-61922-analysis/) 47 - [3] [nowak0x01/PrestaXSRF](https://github.com/nowak0x01/PrestaXSRF) 48 - [4] [Elevating Low Vulnerabilities to Critical in CMSs and E-Commerce Platforms](https://nowak0x01.github.io/papers/76bc0832a8f682a7e0ed921627f85d1d.html)