The message "Plugin: SP Property Finder (com_spproperty) 4.1.3 and below - Unauthenticated SQL Injection (full database read, no fix yet)" appears in mySites.guru.
Is there already an update for the component, or is one currently in development?
Staff replied
Extensions
SP Property - Unauthenticated SQL Injection
1 reply
Ziaul Kabir Staff
Dear Sascha,
Thank you for bringing this to our attention.
We are aware of the reported unauthenticated SQL injection vulnerability affecting SP Property (com_spproperty) 4.1.3 and below. The issue has already been forwarded to our development team for investigation.
At the moment, we cannot confirm a publicly available fixed release yet. Our team is working on the issue, and we will provide an update as soon as a patched version is available.
Thank you for your patience and for helping us bring this security issue to our attention.
Best regards,
Log in to reply.