Support

Admin Tools for WordPress

#41537 SQLiShield protection against SQL injection attacks exeptions

Posted in ‘Admin Tools for WordPress’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

WordPress version
6.7.1
PHP version
8.2.26
Admin Tools version
1.6.7

Latest post by tampe125 on Tuesday, 28 January 2025 03:30 CST

ggaillet

Hello.

The switch to enable SQLiShield protection against SQL injection attacks blocks my Joomunited WP Table manager plugin from sending SQL request to populate a spreadsheet with some data. Turning the SQLiShield protection off solves the problem but is there a way to maintain SQLiShield protection while authorizing this plugin?

Thanks.

tampe125
Akeeba Staff

Hello,

first of all, I'd suggest to use something like phpMyAdmin to interact with your database. It's a battle proof tool with a lot of testing and securities, so if you have to pass raw data to the database, that should be your first choice.

That being said, you can create a WAF exception inside Admin Tools to allow those requests. Please take a look at this page of the docs, you will have to understand exactly which URL is called so you can create a rule to disable the WAF: https://www.akeeba.com/documentation/atwp/wafexceptions.html 

Davide Tampellini

Developer and Support Staff

🇮🇹Italian: native 🇬🇧English: good • 🕐 My time zone is Europe / Rome (UTC +1)
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!