SQL Injection Attempt and Security
-
So, yesterday, we had a site that uses your GetPaid addon, and we had a drive by SQL injection attempt. From what we can see, the addon creates invoices whether the attempt to pay is successful or not. With no captcha on your plugin, what other options are open to us to secure these forms better.
Right now, the plugin feels unusable if drive by attacks can destroy our mail rep (due to a multitude of emails about new invoices after the attack), and mass fill invoices creating an insecure environment of junk code.
Thoughts?
Viewing 6 replies - 1 through 6 (of 6 total)
Viewing 6 replies - 1 through 6 (of 6 total)
- The topic ‘SQL Injection Attempt and Security’ is closed to new replies.