daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

prestashop.md (3409B)


      1 ---
      2 title: "PrestaShop"
      3 section: "Network Services"
      4 sectionSlug: "network-services-pentesting"
      5 sourcePath: "src/network-services-pentesting/pentesting-web/prestashop.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/network-services-pentesting/pentesting-web/prestashop.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # PrestaShop
     14 
     15 ## From XSS to RCE
     16 
     17 PrestaXSRF automates cross-site request forgery chains that turn an existing back-office XSS into higher-impact actions on PrestaShop 1.7.x and 8.x. Its `PSUploadModule()` workflow causes an authenticated administrator's browser to upload a malicious module, resulting in persistent code execution.<sup>[[3]](#references)[[4]](#references)</sup>
     18 
     19 ## ps_checkout ExpressCheckout silent login account takeover (CVE-2025-61922)
     20 
     21 Missing identity validation in the `ps_checkout` Express Checkout flow allows an unauthenticated attacker to switch the current storefront session to a customer account by supplying that customer's email address. Affected releases are `>= 1.3.0, < 4.4.1` and `>= 5.0.0, < 5.0.5`; versions 4.4.1 and 5.0.5 contain the fix.<sup>[[1]](#references)[[2]](#references)</sup>
     22 
     23 - **Unauthenticated endpoint:** `POST /module/ps_checkout/ExpressCheckout`.
     24 - **Flow:** `ExpressCheckout.php` accepts attacker JSON, only checks `orderID`, builds `ExpressCheckoutRequest` and calls `ExpressCheckoutAction::execute()`.
     25 - **Authentication bug:** In vulnerable versions, `ExpressCheckoutAction` calls `CustomerAuthenticationAction::execute()` when no customer is logged in. The vulnerable flow effectively performs `customerExists(<payer_email>)` followed by `context->updateCustomer(new Customer($id))`, updating the customer context without verifying a password or token.
     26 - **Attacker-controlled email field:** `order.payer.email_address` inside the JSON payload is read by `ExpressCheckoutRequest::getPayerEmail()`.
     27 
     28 ### Exploitation steps
     29 
     30 1. Collect any registered customer email (admin is separate and not affected by this flow).
     31 2. Send an unauthenticated POST to the controller with `orderID` plus the victim email in `order.payer.email_address`.
     32 3. Capture the returned session cookies. In the demonstrated flow, the customer context is updated even when the endpoint later returns `500`, allowing access to the victim's storefront account. Depending on the data and actions exposed by that shop, this can disclose the customer's personally identifiable information or permit purchases through payment methods already available to the account.<sup>[[2]](#references)</sup>
     33 
     34 ```http
     35 POST /module/ps_checkout/ExpressCheckout HTTP/1.1
     36 Host: <target>
     37 Content-Type: application/json
     38 Content-Length: 72
     39 
     40 {"orderID":"1","order":{"payer":{"email_address":"victim@example.com"}}}
     41 ```
     42 
     43 ## References
     44 
     45 - [1] [GitHub Security Advisory GHSA-54hq-mf6h-48xh: PrestaShop Checkout account takeover](https://github.com/PrestaShopCorp/ps_checkout/security/advisories/GHSA-54hq-mf6h-48xh)
     46 - [2] [Ananda Dhakal: CVE-2025-61922 technical analysis](https://dhakal-ananda.com.np/blogs/cve-2025-61922-analysis/)
     47 - [3] [nowak0x01/PrestaXSRF](https://github.com/nowak0x01/PrestaXSRF)
     48 - [4] [Elevating Low Vulnerabilities to Critical in CMSs and E-Commerce Platforms](https://nowak0x01.github.io/papers/76bc0832a8f682a7e0ed921627f85d1d.html)