Hello,
This is more of a false positive. They are changing the filter value from ASC / DESC to a word that doesn't exist in the order by clause hence the failover. If they tried to execute SQL any SQL Injection would be filtered within it.
I'll make a change to ensure this filter only accepts ASC/DESC however in future versions.
Many thanks
Tony
JEvents Club members can get priority forum support at the Support Forum. As well as access to a variety of custom JEvents addons and benefits.
Join the JEvents club today!Join the JEvents club today!