Impact
The vulnerability resides in the SP Page Builder extension for Joomla and manifests through improper validation of the 'catid' parameter in the loadMoreArticles endpoint. An attacker can supply malicious input to inject arbitrary SQL statements, enabling unauthorized execution of database queries that can read, modify, or delete sensitive data stored within the Joomla site's database. This type of injection can compromise the confidentiality, integrity, and availability of the site’s data and, if the database user has extensive privileges, can act as a pivot to more serious system compromise.
Affected Systems
All installations of the SP Page Builder extension for Joomla with a version earlier than 6.8.0 are affected. The extension is distributed by joomshaper.com, and any Joomla site using a pre‑6.8.0 build of this extension is vulnerable.
Risk and Exploitability
The CVSS score of 9.2 rates this flaw as critical. The EPSS score is <1%, indicating that while exploitation is unlikely, the high severity demands rapid action. The vulnerability is not listed in the CISA KEV catalog. An attacker only needs network access to the web server and can target the loadMoreArticles route directly via HTTP requests, without authentication. If exploited, the attacker could obtain or alter the site’s database contents and potentially use the database privileges to attack other parts of the infrastructure.
OpenCVE Enrichment