Impact
An unauthenticated attacker can submit malicious JavaScript to the Shapes API endpoint of the SP Page Builder extension for Joomla. The payload is stored in the site database and executes automatically in the browser when an administrator opens the editor, enabling the attacker to hijack admin sessions, exfiltrate credentials, or deface the site.
Affected Systems
The vulnerability affects the SP Page Builder extension provided by joomshaper.com for Joomla, specifically any installation running a version earlier than 6.7.0.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. An unauthenticated attacker can trigger the flaw simply by sending a crafted HTTP request to the endpoint; no further credentials or permissions are required, making exploitation straightforward for anyone with network access to the site.
OpenCVE Enrichment