Security issue: Hacking via submission in OJS 2.4.8

Yes. I kept the default dir. So it is indeed web accessible but I can’t really chose another one because I’m on a shared host. If I put
Order allow,deny
Deny from all
in .htaccess could it be sufficient?

Yours