Medium severity6.8NVD Advisory· Published Dec 3, 2020· Updated Jun 17, 2026
CVE-2020-26248
CVE-2020-26248
Description
In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve data or stop the MySQL service. The problem is fixed in 4.2.1 of the module.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
prestashop/productcommentsPackagist | >= 4.0.0, < 4.2.1 | 4.2.1 |
Affected products
3cpe:2.3:a:prestashop:productcomments:*:*:*:*:*:prestashop:*:*+ 1 more
- cpe:2.3:a:prestashop:productcomments:*:*:*:*:*:prestashop:*:*range: <4.2.1
- (no CPE)range: >= 4.0.0, < 4.2.1
Patches
Vulnerability mechanics
References
7- github.com/PrestaShop/productcomments/commit/7c2033dd811744e021da8897c80d6c301cd45ffanvdPatchThird Party AdvisoryWEB
- packetstormsecurity.com/files/160539/PrestaShop-ProductComments-4.2.0-SQL-Injection.htmlnvdExploitThird Party AdvisoryVDB EntryWEB
- github.com/PrestaShop/productcomments/releases/tag/v4.2.1nvdRelease NotesThird Party AdvisoryWEB
- github.com/PrestaShop/productcomments/security/advisories/GHSA-5v44-7647-xfw9nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-5v44-7647-xfw9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-26248ghsaADVISORY
- packagist.org/packages/prestashop/productcommentsnvdRelease NotesThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.