CVE-2024-36626
Prestashop vulnerability analysis and mitigation

Overview

In PrestaShop version 8.1.4, a NULL pointer dereference vulnerability was identified in the math_round function within Tools.php. The vulnerability was discovered on November 29, 2024 (NVD).

Technical details

The vulnerability exists in the math_round function within Tools.php where a NULL pointer dereference could occur when calling the round function without proper null checks. The issue was fixed by adding a null coalescing operator to ensure a default value of 0.0 is used when the input is null (PrestaShop Commit).

Impact

A NULL pointer dereference vulnerability can lead to application crashes, resulting in denial of service conditions when the affected function is called with null input.

Mitigation and workarounds

The vulnerability has been patched in a commit that adds a null check using the null coalescing operator (??) to provide a default value of 0.0 when the input is null. Users should update to the patched version when available (PrestaShop Commit).

Additional resources


SourceThis report was generated using AI

Related Prestashop vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-61922CRITICAL9.1
  • PHPPHP
  • cpe:2.3:a:prestashop:prestashop
NoYesOct 16, 2025
CVE-2025-25692MEDIUM6.5
  • PrestashopPrestashop
  • cpe:2.3:a:prestashop:prestashop
NoNoJul 30, 2025
CVE-2025-61923MEDIUM4.1
  • PHPPHP
  • cpe:2.3:a:prestashop:prestashop
NoYesOct 16, 2025
CVE-2025-61924LOW3.8
  • PHPPHP
  • prestashop/ps_checkout
NoYesOct 16, 2025
CVE-2025-51586LOW3.7
  • PHPPHP
  • cpe:2.3:a:prestashop:prestashop
NoYesSep 08, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management