Vulnerability Description
In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve data or stop the MySQL service. The problem is fixed in 4.2.1 of the module.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Prestashop | Productcomments | < 4.2.1 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/160539/PrestaShop-ProductComments-4.2.0-SQLExploitThird Party AdvisoryVDB Entry
- https://github.com/PrestaShop/productcomments/commit/7c2033dd811744e021da8897c80PatchThird Party Advisory
- https://github.com/PrestaShop/productcomments/releases/tag/v4.2.1Release NotesThird Party Advisory
- https://github.com/PrestaShop/productcomments/security/advisories/GHSA-5v44-7647Third Party Advisory
- https://packagist.org/packages/prestashop/productcommentsRelease NotesThird Party Advisory
- http://packetstormsecurity.com/files/160539/PrestaShop-ProductComments-4.2.0-SQLExploitThird Party AdvisoryVDB Entry
- https://github.com/PrestaShop/productcomments/commit/7c2033dd811744e021da8897c80PatchThird Party Advisory
- https://github.com/PrestaShop/productcomments/releases/tag/v4.2.1Release NotesThird Party Advisory
- https://github.com/PrestaShop/productcomments/security/advisories/GHSA-5v44-7647Third Party Advisory
- https://packagist.org/packages/prestashop/productcommentsRelease NotesThird Party Advisory
FAQ
What is CVE-2020-26248?
CVE-2020-26248 is a vulnerability with a CVSS score of 6.8 (MEDIUM). In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve data or stop the MySQL service. The problem is fixed in 4.2.1 of the module.
How severe is CVE-2020-26248?
CVE-2020-26248 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-26248?
Check the references section above for vendor advisories and patch information. Affected products include: Prestashop Productcomments.