PT-2020-16375 · Prestashop · Productcomments

0Xfadam

·

Published

2020-12-03

·

Updated

2022-01-06

·

CVE-2020-26248

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions PrestaShop module "productcomments" versions prior to 4.2.1
Description The issue allows an attacker to use a Blind SQL injection to retrieve data or stop the MySQL service.
Recommendations For PrestaShop module "productcomments" versions prior to 4.2.1, update to version 4.2.1 to resolve the issue.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-26248
GHSA-5V44-7647-XFW9

Affected Products

Productcomments