CVE-2025-51586

MEDIUM4.2EPSS 0.94%

Presta Shop vulnerable to email enumeration

Published: 9/4/2025Modified: 9/15/2025

Description

An issue was discoverd in file controllers/admin/AdminLoginController.php in PrestaShop before 8.2.1 allowing attackers to gain sensitive information via the reset password feature.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM4.2CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

References (10)