Impact
The vulnerability resides in the SP Page Builder extension for Joomla, where improper validation of order parameters in the Dynamic Content endpoint allows attackers to inject arbitrary SQL code. This flaw enables an unauthenticated attacker to manipulate backend database queries, potentially leading to sensitive data exposure, data modification, or even execution of additional SQL commands. The impact is fundamentally a loss of confidentiality, integrity, and availability for the affected Joomla sites, as attacker's control over database content can compromise the entire application.
Affected Systems
The affected systems are installations of the SP Page Builder extension by joomshaper.com running any version prior to 6.7.1. The extension is used within Joomla-based web portals; no other products or plugins are directly mentioned as affected.
Risk and Exploitability
The CVSS score is 9.2, indicating a critical severity. The EPSS score is 0.00237, reflecting a very low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The description specifies that no authentication is required and the attack vector relies on manipulating a publicly accessible order parameter, so the likely attack path is a direct HTTP request to the Dynamic Content endpoint with crafted parameters.
OpenCVE Enrichment