Impact
The vulnerability allows an unauthenticated attacker to create arbitrary directories and files with a predetermined name on the web server hosting the Joomla site. Because no authentication is required, the flaw can be triggered by any user with network access to the site, potentially enabling unauthorized file placement or overwriting of existing files. This behavior is a classic Path Traversal weakness (CWE‑22) and may serve as a foothold for additional exploits such as script injection or data tampering.
Affected Systems
The flaw affects the SP Page Builder extension distributed by joomshaper.com for the Joomla content management system. Versions older than 6.8.0 are vulnerable; specific sub‑versions were not listed. Any Joomla installation using the vulnerable extension is at risk.
Risk and Exploitability
The CVSS score of 6.3 indicates medium severity, and no EPSS score is available, so the likelihood of exploitation cannot be quantified. The vulnerability is not included in the CISA KEV catalog. The attack vector is inferred to be remote web‑based, as the flaw can be triggered through unauthenticated HTTP requests to the affected component. The absence of authentication requirements means that any external user can trigger the directory and file creation, posing a measurable threat to confidentiality and integrity if additional escalation paths exist.
OpenCVE Enrichment