CVE-2020-26248: Prestashop Productcomments

High severity, CVSS 8.2. EPSS: 12.4% chance of exploitation in the next 30 days.

In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve data or stop the MySQL service. The problem is fixed in 4.2.1 of the module.

Affected products

  • Prestashop Productcomments: before 4.2.1 (fixed in 4.2.1)

Published 2020-12-03. Last modified 2026-06-17.