CVE-2020-26248: Blind SQL injection during the CommentGrade process
Published Dec 3, 2020
·Updated
In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve data or stop the MySQL service. The problem is fixed in 4.2.1 of the module.
Affected Software
1 affected component
Prestashop Productcomments Prestashop<4.2.1
Remediation
Event History
Dec 3, 2020
CVE Published
via MITRE·08:55 PM
Data Sourced
via MITRE·08:55 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this PrestaShop module?
The vulnerability ID for this PrestaShop module is CVE-2020-26248.
2
What is the severity rating of CVE-2020-26248?
The severity rating of CVE-2020-26248 is high, with a value of 8.2.
3
How does CVE-2020-26248 affect PrestaShop module productcomments?
CVE-2020-26248 affects PrestaShop module productcomments before version 4.2.1.
4
What is the risk associated with CVE-2020-26248?
The risk associated with CVE-2020-26248 is that an attacker can use a Blind SQL injection to retrieve data or stop the MySQL service.
5
How can I fix CVE-2020-26248?
You can fix CVE-2020-26248 by updating the productcomments module to version 4.2.1 or above.