Impact
The SP Page Builder extension lacks directory confinement for file uploads; the folder request parameter completely overrides the generated date‑based destination folder and is passed to Folder::create() and File::upload() without the boundary checks used elsewhere in the file. As a result, an attacker can write files to any directory beneath the web root, including administrator/, templates/, cli/ and the site root, while Joomla’s input filter prevents traversal above the web root and existing files are not overwritten.
Affected Systems
SP Page Builder (Free and Pro) extension for Joomla in versions 4.0.0 through 6.9.0.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. EPSS data is not available; the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a web‑based file upload upload privileges is required. An attacker who can submit a file upload via the extension could place scripts or other executable files in a writable directory within the web root, potentially leading to remote code execution. The primary impact is an arbitrary file write below the web root, constrained only by Joomla’s PATH input filter which blocks traversal above the web root and prevents overwriting existing files.
OpenCVE Enrichment