Impact
The SP Property extension for Joomla versions older than 4.1.4 contains an input validation flaw where gallery image management controller tasks do not enforce directory confinement. This omission allows an attacker to craft requests that access files outside the intended gallery directory, leading to unauthorized reading of arbitrary files on the server. The weakness aligns with CWE‑22, exposing confidentiality of sensitive data stored on the web host.
Affected Systems
The vulnerability affects the joomshaper.com SP Property extension for Joomla. All installations running a version earlier than 4.1.4 are potentially impacted. The affected product is list specifically by its vendor and version, and no further product variants are noted.
Risk and Exploitability
The CVSS score of 6.9 classifies the issue as moderate severity. The EPSS score is not available, so the exploitation probability cannot be quantified, yet the lack of directory confinement suggests that an authenticated administrator could exploit the flaw. The vulnerability is not listed in the CISA KEV catalog, indicating no publicly known active exploitation at this time. The attack vector is likely through the gallery image management interface, which is accessed via HTTP requests by users with Joomla administrative privileges. If an attacker gains such access, they could read sensitive files beyond the gallery scope.
OpenCVE Enrichment