Impact
The vulnerability allows an attacker without any authentication to create comments on a Joomla site that has disabled guest commenting. By supplying user controlled input that overrides the setting responsible for permitting guest comments, the malicious user can post arbitrary content. This flaw is an Access Control weakness (CWE‑284) that can be exploited to deliver spam, phishing content, or other unwanted messages. In the worst case, repeated comments could clutter the site, degrade user experience, and potentially serve as a vector for social engineering attacks.
Affected Systems
The flaw affects the SP Page Builder extension developed by joomshaper.com for Joomla, versions prior to 6.8.0. Hosts using any of these affected releases are susceptible to the unauthorized comment creation behaviour. No specific minor or patch versions are listed, so all releases below 6.8.0 should be considered vulnerable.
Risk and Exploitability
The CVSS score of 6.3 classifies this as a moderate severity issue. The EPSS metric is currently unavailable, and the vulnerability is not in the CISA KEV catalog. The attack is simple: an unauthenticated user sends a normal comment creation request containing an override flag that forces the system to accept the comment. No additional privileges or local environmental conditions are required, making the exploit highly likely in a publicly exposed Joomla site that hosts the vulnerable extension.
OpenCVE Enrichment