lowVulnerability

GHSA-mqq7-wxx5-mp8h

### Impact Unvalidated parameter can lead to some unauthorized method invocation with very little possibilities. ### Patches The problem has been patched in versions - v5.3.0 for PrestaShop 1.7 (build number: 7.5.3.0) - v5.3.0 for PrestaShop 8 (build number: 8.5.3.0) - v5.3.0 for PrestaShop 9 (build number: 9.5.3.0) Read the [Versioning policy](https://github.com/PrestaShopCorp/ps_checkout/wiki/Versioning) to learn more about the build numbers. ### Credits PrestaShop thanks [PATICEO](https://www.paticeo.com/) for reporting the issue.

Properties

ghsa_id
GHSA-mqq7-wxx5-mp8h
severity
low
summary
ps_checkout allows unauthorized method invocation through unvalidated parameter
cve_id
GHSA-mqq7-wxx5-mp8h
is_ghsa_only
true
ghsa_published
2026-04-30T20:59:28Z
source_url
https://github.com/advisories/GHSA-mqq7-wxx5-mp8h
ghsa_updated
2026-04-30T20:59:29Z

Related Entities (4)

VULNERABLE_TO (1)

[Software]composer/prestashop/ps_checkout

AFFECTS (1)

[Software]composer/prestashop/ps_checkout

HAS_WEAKNESS (1)

[Weakness]Improper Input Validation

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph