Chronoconnectivity Vulnerable to SQL Injection?

luxhodge 06 Feb, 2014
Anyone see this about the vulnerability of chronoconnectivity to an SQL Injection attack? http://xforce.iss.net/xforce/xfdb/59079.

Is there any solution to this? Will this be addressed in a future update? Is this still an issue if the view of your table using CC is from a protected user view? In other words not a public user but a higher level registered type user only? Just want to know how to make my CC views secure. Thanks in advance for any help.

Erik
GreyHead 07 Feb, 2014
Hi Erik,

Not something that I had seen before - you might send it to Max using the Contact Us link in case he doesn't see it here.

I notice that the example they give is a Joomla! menu link so I'm not clear whether the vulnerability is in the main router or in CC.

Bob
luxhodge 11 Feb, 2014
Answer
UPDATE: talked to Max on this. He said CCv5 is safe for sure. He is double checking CCv4, but he is pretty sure he checked all of the vulnerabilities. I might email the website where this was listed to let them know this is not an issue.
This topic is locked and no more replies can be posted.