Presta Shop vulnerable to email enumeration
Moderate severity
GitHub Reviewed
Published
Sep 4, 2025
in
PrestaShop/PrestaShop
•
Updated Sep 4, 2025
Description
Published to the GitHub Advisory Database
Sep 4, 2025
Reviewed
Sep 4, 2025
Last updated
Sep 4, 2025
Impact
An unauthenticated attacker with access to the back-office URL can manipulate the id_employee and reset_token parameters to enumerate valid back-office employee email addresses.
Impacted parties:
Store administrators and employees: their email addresses are exposed.
Merchants: risk of phishing, social engineering, and brute-force attacks targeting admin accounts.
Patches
PrestaShop 8.2.3
Workarounds
You must upgrade, or at least apply the changes from the PrestaShop 8.2.3 patch. More information: https://build.prestashop-project.org/news/2025/prestashop-8-2-3-security-release/
References