Impact
The vulnerability is a second‑order SQL injection in the loadStyles method of the Page Builder CK frontend model. An attacker can submit crafted input that is later embedded in a database query, allowing execution of arbitrary SQL statements. This can lead to disclosure of sensitive data, modification of database contents, or, in some configurations, escalation to remote code execution. The weakness is a classic input validation failure as identified by CWE‑89.
Affected Systems
The affected product is the Page Builder CK extension for Joomla, produced by joomlack.fr. Versions of the extension older than 3.6.5 are impacted. No additional vendor or version details are supplied beyond the extension name and the cutoff version.
Risk and Exploitability
With a CVSS score of 9.3, the vulnerability is considered critical and high risk to affected sites. No EPSS score is available, but the lack of mitigation instructions from the vendor suggests an exploitable condition may be present in production environments. The attack vector is inferred to be remote via the front‑end; an attacker can inject payloads through rendered page parameters. Because it is not listed in the CISA KEV catalog, there is no confirmed exploitation in the wild, but the high severity warrants immediate attention.
OpenCVE Enrichment