SQLI Injections with community events plugin

Home Forums Calendar Products Community Events SQLI Injections with community events plugin

Viewing 3 posts - 1 through 3 (of 3 total)
  • Author
    Posts
  • #1184112
    Matt
    Participant

    We are using the Community Events plugin alongside The Events Calendar Pro for a site and have found that users have attacked our site using the field: “VENUE DETAILS: Use Saved Venue:”.

    Can the plugin makers please confirm if all input fields are properly sanitised in this plugin and all their other event plugins, and let us know how we can stop people from inserting scripts?

    …into our fields and and ensure they can’t compromise the site using this attack method?

    #1184381
    Nico
    Member

    This reply is private.

    #1194878
    Support Droid
    Keymaster

    Hey there! This thread has been pretty quiet for the last three weeks, so we’re going to go ahead and close it to avoid confusion with other topics. If you’re still looking for help with this, please do open a new thread, reference this one and we’d be more than happy to continue the conversation over there.

    Thanks so much!
    The Events Calendar Support Team

Viewing 3 posts - 1 through 3 (of 3 total)
  • The topic ‘SQLI Injections with community events plugin’ is closed to new replies.