Active SQL injection vulnerability - Forum | JoomShaper
Solved SP Page Builder

Active SQL injection vulnerability

Asked by komir 1 month ago Last activity 1 month ago

Hello,

I use mysites.guru to maintain my websites, and I have just received a critical security warning regarding SP Page Builder v6.7.1.

According to the security alert, version 6.7.1 contains an active, unauthenticated SQL injection vulnerability in the front-end article loading endpoint (articles.loadMoreArticles), which is reportedly being actively exploited in the wild.

Could you please provide an estimated timeframe for when version or patch will be officially released and available for download?

Thank you for your prompt response regarding this critical issue.

Best regards

Accepted answer

Marked as the solution
Paul Frankowski Senior Staff

Yes, it should be today, I hope very soon.

If somebody needs fixed file (sooner) I put inside "Hidden Content" , look below

Easy Connect 83

Hello,
I don't see any hidden content in your post to access the patch.

6 more replies

Easy Connect 83

Hello, I’m in the same situation. I also use the MySites.guru service.

I reported it to them yesterday.

They replied saying they would offer an update this morning...

Paul Frankowski Senior Staff

Becuase it wasn't your topic.

Shared on your e-mail already

Easy Connect 83

Thanks

MiBa

Wouldn't it be advisable to publish the patch in the Downloads section for all until version 6.8.0 is released, and create a locked forum topic with a link?

David Forés

The logical thing would have been for them to release version 6.7.2 to fix the critical vulnerability, and then release 6.8.0 once it was ready with the rest of the fixes and improvements.

copycat

Mysites Guru was on vacation from July 30 to August 10, and we had about ten days of peace — all of us in the Joomla community. Now we’re back to daily patching, updates, and so on. Yesterday, I posted on JoomShaper’s Facebook page warning that the guy is back from vacation and that we’re starting again as before.

Rvdzande

Well you could also turn it around.

If a crime gets commited and there is no police to do an arrest? Should we than still not qualify it as a crime?

I have no affiliation or relation with MySites.Guru but I think this site and htproject are doing a good job. They are reporting things to keep a site safe. If they report or not doesnt change anything to their price or service, so I don't see the issue here. The issue is in the software flaws (which will always be happening because humans just make mistakes).

Log in to reply.