Impact
The vulnerability is an authenticated SQL injection that allows an actor with valid Joomla credentials to manipulate database queries through the SP Page Builder extension’s media manager search and date filter parameters. By injecting crafted input, an attacker can read, modify, or delete database records, potentially compromising site content, user data, or administrative settings. The weakness is a classic input validation flaw as specified by CWE-89.
Affected Systems
The affected product is the SP Page Builder extension for Joomla published by joomshaper.com. Versions prior to 6.7.1 are susceptible; no other version information is available in the report.
Risk and Exploitability
The CVSS score of 8.2 highlights a high severity, and the EPSS score of 0.00226 indicates a very low but non‑zero exploitation probability. The lack of KEV listing does not diminish the risk for environments running the vulnerable extension. As an attacker must be authenticated, the likelihood of exploitation depends on the attacker’s ability to acquire valid credentials. Once authenticated, the injection can be performed via the media manager interface leading to potential data tampering or exfiltration.
OpenCVE Enrichment