Prestashop是美国Prestashop公司的一套开源的电子商务解决方案。该方案提供多种支付方式、短消息提醒和商品图片缩放等功能。 PrestaShop productcomments module 4.2.1之前版本存在SQL注入漏洞,攻击者可利用该漏洞可以使用盲注入SQL来检索数据或停止MySQL服务。这个问题在模块的4.2.1中得到了解决。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| PrestaShop | productcomments | >= 4.0.0, < 4.2.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | PrestaShop Product Comments module before version 4.2.1 contains a SQL injection vulnerability, An attacker can use a blind SQL injection to retrieve data or stop the MySQL service, thereby possibly obtaining sensitive information, modifying data, and/or executing unauthorized administrative operations in the context of the affected site. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-26248.yaml | POC Details |
No public POC found.
Login to generate AI POCHappy to dive into discussions, exchange ideas, and gain fresh perspectives throughout the journey. I'm interested in learning from different perspectives and contributing whenever I can. Happy to hear different experiences and meeting like-minded people. That's my site:<a href="https://automisto24.com.ua/">AutoMisto24</a> https://automisto24.com.ua/