Junglewise Threat Intelligence

CVE-2025-25692: PrestaShop PHAR deserialization in _getHeaders function

CVE-2025-25692 · Severity: medium · CVSS 6.5 · Published 2025-07-30

Technologies: PrestaShop. Vendors: PrestaShop.

Executive brief

PrestaShop is an open-source e-commerce platform used by businesses to create and manage online stores. A security flaw in the software's header processing allows remote attackers to potentially execute unauthorized code on the server. This could lead to a complete takeover of the online store, resulting in the theft of customer data, disruption of business operations, and damage to the company's reputation.

Technical details

A PHAR deserialization vulnerability exists within the '_getHeaders' function of PrestaShop version 8.2.0. The flaw is rooted in the improper neutralization of special elements during the processing of untrusted data, specifically when handling PHP Archives (PHAR). An unauthenticated remote attacker can exploit this by sending a specially crafted POST request to the server. Successful exploitation allows for arbitrary code execution (RCE) or command injection on the underlying host. While the CISA-ADP CVSS score is 6.5 (Medium), the technical impact is categorized as total. Users should monitor for official patches from the PrestaShop maintainers.

Affected products

  • PrestaShop PrestaShop 8.2.0

Timeline

  • 2025-07-30: advisory: NVD published the CVE record

References

Related threats