Impact
The SP LMS extension for Joomla (com_splms) before version 4.1.4 deserializes cookie data supplied by a user without validation, following the CWE‑502 pattern of deserialization vulnerabilities. As a result, an unauthenticated attacker can inject a crafted PHP object into the cookie, causing the server to process it. This flaw enables the attacker to remotely commandeer the entire site, exfiltrate data, or deploy further malware.
Affected Systems
JoomShaper’s SP LMS extension for Joomla is affected. All deployments running any version earlier than 4.1.4 are vulnerable. The extension is hosted by joomshaper.net and packaged under the product name SP LMS extension for Joomla.
Risk and Exploitability
The CVSS score of 9.5 indicates a high severity. The EPSS score of 8% reflects a moderate exploitation probability, and combined with the flaw’s unauthenticated nature suggests a significant risk. The vulnerability is not listed in the CISA KEV catalog. Attackers can simply craft a malicious cookie; when the vulnerable server unserializes this input it can execute arbitrary code, granting full control over the affected host.
OpenCVE Enrichment