Chronoconnectivity Vulnerable to SQL Injection?

Secure ChronoConnectivity against SQL injection vulnerabilities.

Overview

The concern was about potential SQL injection risks in older versions of ChronoConnectivity.
Ensure you are using ChronoConnectivity v5, which is confirmed safe, and verify that v4 has been patched for all known vulnerabilities.

Answered
lu luxhodge 06 Feb, 2014
Anyone see this about the vulnerability of chronoconnectivity to an SQL Injection attack? http://xforce.iss.net/xforce/xfdb/59079.

Is there any solution to this? Will this be addressed in a future update? Is this still an issue if the view of your table using CC is from a protected user view? In other words not a public user but a higher level registered type user only? Just want to know how to make my CC views secure. Thanks in advance for any help.

Erik
Gr GreyHead 07 Feb, 2014
Hi Erik,

Not something that I had seen before - you might send it to Max using the Contact Us link in case he doesn't see it here.

I notice that the example they give is a Joomla! menu link so I'm not clear whether the vulnerability is in the main router or in CC.

Bob
lu luxhodge 11 Feb, 2014
Answer
UPDATE: talked to Max on this. He said CCv5 is safe for sure. He is double checking CCv4, but he is pretty sure he checked all of the vulnerabilities. I might email the website where this was listed to let them know this is not an issue.
This topic is locked and no more replies can be posted.