Impact
In SP Property 4.1.3 and earlier a booking inquiry form relied on client‑supplied hidden fields to determine the email recipient. An attacker can modify those fields, resulting in emails being sent to arbitrary addresses. The flaw is an information‑exposure weakness (CWE‑201) that can lead to unauthorized disclosure or phishing of booking data, and may also facilitate denial of service by interfering with legitimate notifications.
Affected Systems
The Joomla extension SP Property from joomshaper.com, versions prior to 4.1.4, is affected. Any site using this extension with the default configuration can be impacted.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity vulnerability. While the EPSS score is not available, the issue is not listed in the CISA KEV catalog, suggesting it may not yet be broadly exploited. The likely attack vector is a web‑application input, requiring the attacker to craft a booking request form that manipulates hidden fields. Successful exploitation would allow the attacker to redirect booking notifications to arbitrary addresses, potentially leaking sensitive information or executing phishing attacks.
OpenCVE Enrichment