Announcement

Collapse
No announcement yet.

Imunify blocking Ninja form submissions

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • Imunify blocking Ninja form submissions

    Hi there,

    We setup a new website on our server and Imunify is blocking Ninja form submissions and suspects them of being a MSSQL code execution. This is a standard Wordpress site and the first time Ive run across this:

    Code:
    [client 00.00.00.00] ModSecurity: [file "/etc/httpd/conf/modsecurity.d/rules/custom/001_i360_1_generic.conf"] [line "174"] [id "77211650"] [msg "IM360 WAF: Detects MSSQL code execution and information gathering attempts||MVN:ARGS:form||MV:{\"id\":2,\"show_publish_options\":false,\"fields\":[{\"settings\":{\"objectType\":\"Field\",\"objectDomain\":\"fields\",\"editActive\":false,\"order\":1,\"label\":\"Tell us about your project\",\"key\":\"tell_us_about_your_project_1597863809067\",\"type\":\"html\",\"created_at\":\"2016-04-18 14:54:49\",\"default\":\"<h3>Tell us about your project...</h3>\",\"container_class\":\"\",\"element_class\":\"\",\"field_label\":\"Tell us about your project\",\"field_key\":\"tell_us_about_your_project\"},\"id\":5},{\"settings\":{\"objectType\":\"Field\",\"objectDomain\":\"fields\",\"editActive\":false,\"order\":2,\"label\":\"Which package would you like to start with?\",\"key\":\"which_package_would_you_like_to_start_with_1597863490774\",\"type\":\"listradio\",\"created_at\":\"2016-04-18 14:54:49\",\"label_pos\":\" [hostname "abc.com"] [uri "/wp-admin/admin-ajax.php"] [unique_id "X01iABfZyN4FMNl4eC3mJwAAAQM"], referer: [URL]https://abc.com/wp-admin/admin.php?page=ninja-forms&form_id=2[/URL]
    Any thoughts on how to resolve this?

    Thanks
    G

  • #2
    Hello Glenn,
    Thank you for reaching out! Please try to disable the rule 77211650 for the problem domain here Settings>Disabled rules. This is described in our documentation https://[https://docs.imunify360.com...disabled-rules.
    And could you also create a support ticket https://cloudlinux.zendesk.com/hc/en-us/requests/new? so we can look at false-positive. If you have any other questions, feel free to ask here.
    Thank you for contacting us.](https://docs.imunify360.com/dashboard/#disabled-rules)

    Comment

    Working...
    X