Impact
The Page Builder CK extension for Joomla includes an unsanitized input vulnerability in its styles model that enables a SQL injection attack. An attacker who can supply crafted input to the affected parameter could read, modify, or delete database contents, potentially compromising site data integrity, confidentiality, and availability. This flaw maps to CWE-89.
Affected Systems
The vendor joomlack.fr offers the Page Builder CK extension for Joomla. Versions earlier than 3.6.5 are vulnerable; the front‑end component is fixed in 3.6.4, while the back‑end is fixed in 3.6.5. All earlier releases remain at risk.
Risk and Exploitability
The CVSS score of 9.3 classifies this flaw as critical, and while the EPSS score is not published, the lack of a KEV listing does not diminish the need for urgent action. The likely attack vector is through user-supplied input to the styles model on either the front‑end or back‑end, which an attacker could exploit without authentication or with minimal privileges. Once exploited, an attacker can gain full database control, facilitating data theft, site defacement, or further lateral movement.
OpenCVE Enrichment