[Locked] ๐’๐ ๐๐š๐ ๐ž ๐๐ฎ๐ข๐ฅ๐๐ž๐ซ ๐’๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ ๐๐š๐ญ๐œ๐ก ๐š๐ง๐ ๐Œ๐š๐ง๐ฎ๐š๐ฅ ๐…๐ข๐ฑ ๐ƒ๐ž๐ญ๐š๐ข๐ฅ๐ฌ - Forum | JoomShaper
Staff replied General Locked

๐’๐ ๐๐š๐ ๐ž ๐๐ฎ๐ข๐ฅ๐๐ž๐ซ ๐’๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ ๐๐š๐ญ๐œ๐ก ๐š๐ง๐ ๐Œ๐š๐ง๐ฎ๐š๐ฅ ๐…๐ข๐ฑ ๐ƒ๐ž๐ญ๐š๐ข๐ฅ๐ฌ

Asked by Toufiq 3 months ago Last activity 3 months ago

Following our previous security announcement for SP Page Builder v6.6.2, weโ€™re sharing the exact patch details for users who need to review or apply the fix manually.

These changes fully secure the affected controller endpoint.

Affected file:

components/com_sppagebuilder/controllers/asset.php

Download & replace the patch file:

https://gist.github.com/ahamed/b45bd9605d81064b1f1a751ee23e4bd4

We still strongly recommend updating to the latest SP Page Builder version instead of manually replacing files.

Go to:

System -> Update -> Extensions

If you are already using SP Page Builder v6.6.2 or later, no further action is required.

Thank you for keeping your Joomla websites safe. ๐Ÿ™Œ

16 replies

Chriss

WOW, ONE WEEK LATER!

Ofi Khan Staff

Hello Chriss

Apology for the delay. We heard your voice and felt the necessity for a free patch. If you have an active SP Page Builder subscription, then you need to update the version to 6.6.2. No further action needed.

If you do not have a subscription, only then use the patch. Just the change the file contents of components/com_sppagebuilder/controllers/asset.php and the site will be safe again.

Thanks for keeping your trust in us.

Best regards

David Forรฉs

Just to clarify, when you say that โ€œno further action is needed,โ€ you should specify that this applies only if the website hasnโ€™t been hacked. In that case, itโ€™s true that simply updating the version would be enough.

But if the site has been hacked, no matter how much you update SP Page Builder, the attackers already have complete control over your site and have likely left several hidden backdoors through which they can re-enter. In this case, there is indeed a LOT of work to be done.

Toufiq Senior Staff

Thank you for pointing this out. You are right, we should clarify that no further action is needed applies only to websites that were not compromised and have simply updated to the patched version.

If a website was already compromised before applying the update, additional security checks are required, as updating only fixes the vulnerability but does not automatically remove any existing malicious files or changes.

We appreciate your clarification and will make sure our communication is clearer on this point.

Chriss

โ€œThanks for continuing to trust us.โ€

No, you've lost that trust. Once again, your help is way too late! The honest answer would have been to delete everything, restore the backup, and buy the update. Don't just slap a file together a week later! Sticking with SP PageBuilder is a mistake!

Toufiq Senior Staff

Weโ€™re really sorry for the frustration and inconvenience this has caused. We understand your concern, and this is not the experience we want you to have.

The fix was already included in the v6.2.2 patch release. The file we shared separately is the same fixed file for users who need a quick manual solution without going through the full update process.

We truly appreciate your patience and feedback. Weโ€™ll continue working to improve our release and support process.

Anke Sauer

Yes, I have to agree with that.
Iโ€™m now dealing with a huge mess across many of my clientsโ€™ websites. And as is often the case with clients, they didnโ€™t necessarily back up their data after their last updates.
I canโ€™t even bill them for my work while Iโ€™m sitting here trying to get everything back on track.
This really shouldnโ€™t happenโ€”after all, theyโ€™re putting a lot of money into this, not to mention their trust.
My clients trust me, too, and now I have to explain to them why the sites arenโ€™t working anymore. Thatโ€™s it, then.
Thanks a lot for that.

Chriss

I can only recommend rebuilding your website and uninstalling SP PageBuilder as soon as possible. Iโ€™ve taken down 6 sites so far, and as you can see here, the effort has totally paid off. The last two are going down now!

Toufiq Senior Staff

We sincerely apologize for the trouble and frustration this has caused. We understand how difficult this situation is when managing multiple client websites, and we truly regret the inconvenience.

The fix has already been included in the v6.2.2 patch update. We also shared the specific fixed file separately to help affected users resolve the issue faster.

If any websites are still having issues, please share the details with us. Our team will do our best to help you get everything back on track.

Thank you for your feedback. We take this seriously and will continue improving our release process.

ANT
3 months ago ยท edited

Thanks for all.
I have an old j3 and sppb 3.8.10 (I know)
is this normal that asset.php does not exist ?

Toufiq Senior Staff

If you are using Page Builder 3, you donโ€™t need to worry about this security update.

ANT

the mail sent today was about joomla 3 and sppb3

Mike Lawson

Figured Id take a break from fixing my client's hacked websites and chime in on the matter.

Ever considered offering credits to your loyal subscribers? Constantly apologizing over and over is more insulting than it is comforting.

Paul Frankowski Senior Staff

@Chris, not really! This is free path for webmasters without active SPPB subsctiption.

And as you may know, not all developers do that.

Paul Frankowski Senior Staff
3 months ago ยท edited

It was general info that you are using old versions on your own risk. We don't update and improve extensions for J3 anymore.

Paul Frankowski Senior Staff
3 months ago ยท edited

What do you mean saying "credits" ? as I know every software had or will have security holes. Even big ones from Top 100, Windows or Android included!. In this comparison, we are a small "player". And the Joomla market share is only getting smaller every year, not growing :/ Such security problems, therefore, are painful for both sides. Believe me, I'd rather answer the question โ€œHow do I change the button color?โ€ 100 times than read about a website being hackedโ€”whether it's because of us or for some other reason.


@Mike, We talk about that face-to-face on Joomla Day 2026, if you will be there.

Mike Lawson

Credits as in crediting money people pay you for using your product that is completely compromised.
Ive never encountered a Joomla plugin or component with such a gaping security flaw..until now.

Anyways, any idea how I can stop my website from being hacked?? Something is hacking my root folder and adding .html files and folders...and erasing my .htaccess file. I have V6.6.2 installed and Im still getting hacked!

Ahmad Moussa

Hello Toufiq, please is this applied on SP Page Builder 3 on Joomla 3 site?

martin

thatโ€™s a good question

This question is locked, so it takes no new replies. Have a similar problem? Ask a new question.