Low severityNVD Advisory· Published Dec 3, 2020· Updated Aug 4, 2024
Blind SQL injection during the CommentGrade process
CVE-2020-26248
Description
In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve data or stop the MySQL service. The problem is fixed in 4.2.1 of the module.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
prestashop/productcommentsPackagist | >= 4.0.0, < 4.2.1 | 4.2.1 |
Affected products
2- Range: >= 4.0.0, < 4.2.1
Patches
Vulnerability mechanics
Generated on May 9, 2026. Inputs: CWE entries + fix-commit diffs from this CVE's patches. Citations validated against bundle.
References
7- github.com/advisories/GHSA-5v44-7647-xfw9ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-26248ghsaADVISORY
- packetstormsecurity.com/files/160539/PrestaShop-ProductComments-4.2.0-SQL-Injection.htmlghsax_refsource_MISCWEB
- github.com/PrestaShop/productcomments/commit/7c2033dd811744e021da8897c80d6c301cd45ffaghsax_refsource_MISCWEB
- github.com/PrestaShop/productcomments/releases/tag/v4.2.1ghsax_refsource_MISCWEB
- github.com/PrestaShop/productcomments/security/advisories/GHSA-5v44-7647-xfw9ghsax_refsource_CONFIRMWEB
- packagist.org/packages/prestashop/productcommentsghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.