PHAR Deserialization Vulnerability in PrestaShop by PrestaShop
CVE-2025-25692

6.5MEDIUM

Key Information:

Vendor

PrestaShop

Vendor
CVE Published:
30 July 2025

What is CVE-2025-25692?

A vulnerability exists in the _getHeaders function of PrestaShop v8.2.0, wherein improper handling of PHAR files allows attackers to craft a malicious POST request. This could lead to the execution of arbitrary code on the server, putting sensitive data and system integrity at risk. Users are advised to review their installations and apply necessary patches to mitigate potential threats.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.