{"id":"GHSA-mqq7-wxx5-mp8h","aliases":[],"url":"https://o3.security/vulnerability/GHSA-mqq7-wxx5-mp8h","summary":"ps_checkout allows unauthorized method invocation through unvalidated parameter","details":"### Impact\n\nUnvalidated parameter can lead to some unauthorized method invocation with very little possibilities.\n\n### Patches\n\nThe problem has been patched in versions\n\n- v5.3.0 for PrestaShop 1.7 (build number: 7.5.3.0)\n- v5.3.0 for PrestaShop 8 (build number: 8.5.3.0)\n- v5.3.0 for PrestaShop 9 (build number: 9.5.3.0)\n\nRead the [Versioning policy](https://github.com/PrestaShopCorp/ps_checkout/wiki/Versioning) to learn more about the build numbers.\n\n### Credits\n\nPrestaShop thanks [PATICEO](https://www.paticeo.com/) for reporting the issue.","published":"2026-04-30T20:59:28Z","modified":"2026-09-10T03:50:44.645042023Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"prestashop/ps_checkout","fixedVersion":"5.3.0"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/PrestaShopCorp/ps_checkout/security/advisories/GHSA-mqq7-wxx5-mp8h"},{"type":"PACKAGE","url":"https://github.com/PrestaShopCorp/ps_checkout"},{"type":"WEB","url":"https://github.com/PrestaShopCorp/ps_checkout/releases/tag/v5.3.0"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:50:44.645042023Z"}}