Releases18
Frequency6 months 1 week
Last Release
Stars32
PrestaShop module that allows users to post reviews and rate products.

CVE History

CVEPublishedCVSS v3CVSS v2
6.1 MEDIUM

This package is a PrestaShop module that allows users to post reviews and rate products. There is a vulnerability where the attacker could steal an administrator's cookie. The issue is fixed in version 5.0.2.

6.8 MEDIUM6.4 MEDIUM

In the PrestaShop module "productcomments" before version 4.2.1, an attacker can use a Blind SQL injection to retrieve data or stop the MySQL service. The problem is fixed in 4.2.1 of the module.

8.7 HIGH4.3 MEDIUM

In PrestaShop Product Comments before version 4.2.0, an attacker could inject malicious web code into the users' web browsers by creating a malicious link. The problem was introduced in version 4.0.0 and is fixed in 4.2.0