VDB
Sign up
HIGH8.2

GHSA-5v44-7647-xfw9

Blind SQL injection in PrestaShop productcomments module

Quick fix

GHSA-5v44-7647-xfw9 — prestashop/productcomments: upgrade to the fixed version with the command below.

composer require prestashop/productcomments:^4.2.1

Details

### Impact An attacker can use a Blind SQL injection to retrieve data or stop the MySQL service.

### Patches The problem is fixed in 4.2.1

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/prestashop/productcomments
Introduced in: 4.0.0Fixed in: 4.2.1
Fixcomposer require prestashop/productcomments:^4.2.1

References