Dear Sascha,
Thank you for bringing this to our attention.
We are aware of the reported unauthenticated SQL injection vulnerability affecting SP Property (com_spproperty) 4.1.3 and below. The issue has already been forwarded to our development team for investigation.
At the moment, we cannot confirm a publicly available fixed release yet. Our team is working on the issue, and we will provide an update as soon as a patched version is available.
Thank you for your patience and for helping us bring this security issue to our attention.
Best regards,