SP Pagebuilder BUG - Forum | JoomShaper
Staff replied SP Page Builder

SP Pagebuilder BUG

Asked by tonyb2018 2 months ago Last activity 2 months ago

2 replies

Ziaul Kabir Staff

Hello,

We sincerely apologize for the inconvenience caused.

This issue has been fixed in SP Page Builder v6.6.2. Once you upgrade to v6.6.2, this specific vulnerability can no longer be exploited.

However, if your site was compromised before upgrading, simply updating the extension will not remove any malicious files or backdoors that may have already been uploaded. If those files remain on the server, attackers may still be able to access your site. Therefore, it is important to perform a complete cleanup before considering the site secure.

You can also use the following security scanner to help identify malicious files and delete them: https://github.com/zkrana/joomla-security-scanner

Please make sure to read the README.md file in the repository for instructions on how to run the tool.
After completing the cleanup and upgrading to v6.6.2, please let us know the outcome or if you need any further assistance.

We'll be happy to help.
Thank you.

Paul Frankowski Senior Staff

yes, delete all uknown items from folder:
media/com_sppagebuilder/assets/ (weird names, .php, .json etc).

our scanner allows that too, and even more.


Later if you updated everything, install addcional firewall component, just in case.

Log in to reply.