CVE-2020-26248: Prestashop Productcomments
High severity, CVSS 8.2. EPSS: 12.4% chance of exploitation in the next 30 days.
In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve data or stop the MySQL service. The problem is fixed in 4.2.1 of the module.
Affected products
- Prestashop Productcomments: before 4.2.1 (fixed in 4.2.1)
Published 2020-12-03. Last modified 2026-06-17.