Impact
A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, which the application then executes as PHP. The description specifically notes that arbitrary files can be uploaded and run as PHP, implying that the upload endpoint lacks file type restrictions or proper authentication checks.
Affected Systems
The SP Page Builder extension for Joomla from joomshaper.net is vulnerable. No specific version information is provided; therefore all releases of the extension could be impacted.
Risk and Exploitability
The CVSS score of 10 indicates an extremely severe flaw. The EPSS score of 88% indicates a very high likelihood of exploitation. Because the flaw allows unauthenticated uploads with no file type checks, the attack path appears straightforward: an attacker can send a crafted request to the extension's upload endpoint, place a PHP file in the upload directory, and have it executed. The vulnerability is listed in CISA KEV.
OpenCVE Enrichment