What the vulnerability does
01Description
Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager.
CVSS base score
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:L/SC:N/SI:H/SA:L
What the vulnerability does
Joomla Extension - joomshaper.com - Authenticated arbitrary file delete in SP Page Builder < 6.7.1- Improper path validation and ACL checks lead to a file deletion vector in the media manager.
Explanation of Vulnerability in Simple Terms
SP Page Builder for Joomla contains a path traversal vulnerability that allows high-privileged users to read or modify files outside the intended directory. An attacker with administrator access can exploit this to access sensitive configuration files or alter site content. Update to a version newer than 1.0.0-6.7.0 to resolve this issue.
What an attacker can do
Read or modify files outside the intended directory on the server.
Potential impact on your site
Administrators with malicious intent or compromised admin accounts can access sensitive files or alter site data.
Conditions required to exploit
Attacker must have administrator-level access to the Joomla site.
Key dates
External resources
Related vulnerabilities