{"id":"GHSA-5v44-7647-xfw9","summary":"Blind SQL injection in PrestaShop productcomments module","details":"### Impact\nAn attacker can use a Blind SQL injection to retrieve data or stop the MySQL service.\n\n### Patches\nThe problem is fixed in 4.2.1","aliases":["CVE-2020-26248"],"modified":"2026-07-08T06:28:40.655775242Z","published":"2021-01-20T21:33:53Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2021-01-20T21:33:26Z","nvd_published_at":"2020-12-03T21:15:00Z","cwe_ids":["CWE-89"],"severity":"LOW"},"references":[{"type":"WEB","url":"https://github.com/PrestaShop/productcomments/security/advisories/GHSA-5v44-7647-xfw9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-26248"},{"type":"WEB","url":"https://github.com/PrestaShop/productcomments/commit/7c2033dd811744e021da8897c80d6c301cd45ffa"},{"type":"PACKAGE","url":"https://github.com/PrestaShop/productcomments"},{"type":"WEB","url":"https://github.com/PrestaShop/productcomments/releases/tag/v4.2.1"},{"type":"WEB","url":"https://packagist.org/packages/prestashop/productcomments"},{"type":"WEB","url":"http://packetstormsecurity.com/files/160539/PrestaShop-ProductComments-4.2.0-SQL-Injection.html"}],"affected":[{"package":{"name":"prestashop/productcomments","ecosystem":"Packagist","purl":"pkg:composer/prestashop/productcomments"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"4.2.1"}]}],"versions":["v4.0.0","v4.0.1","v4.1.0","v4.2.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/01/GHSA-5v44-7647-xfw9/GHSA-5v44-7647-xfw9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H"}]}