Impact
The Joomla extension Quix Page Builder Pro (v <6.2.1) is vulnerable to unauthenticated SQL injection, enabling an attacker to inject arbitrary SQL statements. This flaw, identified as CWE-89, can let an adversary read, modify, or delete data stored in the site’s database, compromising confidentiality and integrity of the Joomla installation. Based on the description, it is inferred that the injection can be triggered via specially crafted HTTP requests to the extension’s input handling routines.
Affected Systems
The flaw resides in the Quix Page Builder Pro extension distributed by themexpert.com for Joomla, affecting all releases prior to version 6.2.1. Sites running any earlier version are exposed unless a later update is applied.
Risk and Exploitability
With a CVSS score of 8.7, the flaw is classified as high severity. The EPSS score of less than 1% indicates that exploitation is currently rare, although the unauthenticated nature of the attack and its impact on data confidentiality and integrity make it a priority for remediation. The vulnerability is not listed in CISA’s KEV catalog, but an attacker could exploit it from any location with network reach to the site, without needing user accounts. If the database user has elevated privileges, the injected SQL could also be leveraged to further compromise the host.
OpenCVE Enrichment