By intellitech on Thursday, 25 March 2021
Replies 3
Likes 0
Views 1.8K
Votes 0
Please see the attached scanned report and do the needful ASAP.
What's new about this vulnerability?
·
Tuesday, 30 March 2021 10:29
·
0 Likes
·
0 Votes
·
0 Comments
·
Can you please confirm your RSVP Pro Version for testing?

Many thanks
Tony
·
Friday, 02 April 2021 09:20
·
0 Likes
·
0 Votes
·
0 Comments
·
Thank you for highlighting this issue.

I see where this message is coming from and I can assure you that it is not exploitable as an SQL injection because the input is filtered and any SQL or Javascript is removed and the error is caught in the code. What is incorrect is to output an error message as opposed to silently returning no results.

I will resolve this in the next release due in the next few days
·
Monday, 05 April 2021 10:33
·
0 Likes
·
0 Votes
·
0 Comments
·
View Full Post