Impact
An authenticated Joomla user can exploit a SQL injection flaw in the SP Page Builder extension’s content plugin. The plugin reads the sppagebuilder_article_id field from the request and concatenates it directly into a WHERE clause without sanitization read arbitrary database tables, including the users and session tables, thereby compromising user credentials and session data.
Affected Systems
Versions of the SP Page Builder (Free and Pro) extension for Joomla from 5.2.1 through 6.9.0 are affected.
Risk and Exploitability
The flaw receives a CVSS score of 8.6, indicating high severity. EPSS data are not available, and the vulnerability is not listed in the CISA KEV catalog. The vulnerability operation, as the code executes on every onContentAfterSave event regardless of the component that triggered it. Because the injection is time‑based and blind, an attacker does not need direct access to the database but can retrieve sensitive data through response timing. The attack can be carried out in a normal administrative or editorial context, making it a significant threat to sites running the affected plugin.
OpenCVE Enrichment