{"id":"GHSA-58w4-w77w-qv3w","summary":"Reflected XSS with parameters in PostComment","details":"### Impact\nAn attacker could inject malicious web code into the users' web browsers by creating a malicious link.\n\n### Patches\nThe problem is fixed in 4.2.0\n\n### References\n[Cross-site Scripting (XSS) - Reflected (CWE-79) ](https://cwe.mitre.org/data/definitions/79.html)","aliases":["CVE-2020-26225"],"modified":"2026-05-07T05:00:38.527374638Z","published":"2020-11-16T21:23:29Z","database_specific":{"nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2020-11-16T21:22:53Z"},"references":[{"type":"WEB","url":"https://github.com/PrestaShop/productcomments/security/advisories/GHSA-58w4-w77w-qv3w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-26225"},{"type":"WEB","url":"https://github.com/PrestaShop/productcomments/commit/c56e3e9495c4a0a9c1e7dc43e1bb0fcad2796dbf"}],"affected":[{"package":{"name":"prestashop/productcomments","ecosystem":"Packagist","purl":"pkg:composer/prestashop/productcomments"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"4.2.0"}]}],"versions":["v4.0.0","v4.0.1","v4.1.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/11/GHSA-58w4-w77w-qv3w/GHSA-58w4-w77w-qv3w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N"}]}