Impact
The SP Page Builder extension for Joomla does not enforce directory confinement when a media record is renamed. The validation logic only checks that a media record exists for the supplied identifier or that the provided path is present in the media table; it never verifies that the two values correspond to the same file or strips directory traversal sequences. Because the STR input filter preserves traversal characters, an attacker who can reach the rename task can pair any valid media identifier with an unrelated filesystem path. This flaw allows the attacker to rename or replace arbitrary files on the Joomla installation, including critical configuration files such as configuration.php, potentially taking the site offline. The weakness is a directory traversal flaw classified as CWE-22.
Affected Systems
The vulnerability affects Joomla sites that have installed the joomshaper.com SP Page Builder (Free and Pro) extension, versions 4.0.0 through 6.9.0. Any site that contains this extension and exposes the media rename function to administrators is impacted. Users of the extension without any authenticated administrative access cannot reach the vulnerable functionality.
Risk and Exploitability
The vulnerability has a CVSS score of 7, indicating media takes medium‑high severity. The EPSS score of less than 1% suggests that exploitation in the wild is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. To exploit the flaw, an attacker would need access to the media rename task, normally available only to authenticated administrators; this requirement is inferred from the need to invoke the task within the extension. Once access is achieved, the attacker can rename any file for which a media identifier exists, including critical system files, thereby enabling denial of service or further compromise.
OpenCVE Enrichment