Impact
The SP Property extension for Joomla constructs SQL statements by directly concatenating raw request parameters into WHERE and ORDER BY clauses. This omission of quoting or type casting permits an attacker to perform boolean‑based or time‑based blind SQL injection, allowing extraction of arbitrary database contents without authentication.
Affected Systems
The vulnerability affects the Joomla SP Property extension published by joomshaper.com on all versions older than 4.1.4.
Risk and Exploitability
The CVSS score of 9.3 indicates a critical risk, and while an EPSS score is not available, the lack of a KEV listing does not negate the potential for exploitation. Exploitation can be carried out remotely over the internet; an unauthenticated user can submit crafted search or map‑filtering requests that trigger the injection and retrieve sensitive data from the database.
OpenCVE Enrichment