SP Property - Unauthenticated SQL Injection - Forum | JoomShaper
Staff replied Extensions

SP Property - Unauthenticated SQL Injection

Asked by Sascha Langguth 1 month ago Last activity 1 month ago

The message "Plugin: SP Property Finder (com_spproperty) 4.1.3 and below - Unauthenticated SQL Injection (full database read, no fix yet)" appears in mySites.guru.
Is there already an update for the component, or is one currently in development?

1 reply

Ziaul Kabir Staff

Dear Sascha,

Thank you for bringing this to our attention.

We are aware of the reported unauthenticated SQL injection vulnerability affecting SP Property (com_spproperty) 4.1.3 and below. The issue has already been forwarded to our development team for investigation.

At the moment, we cannot confirm a publicly available fixed release yet. Our team is working on the issue, and we will provide an update as soon as a patched version is available.

Thank you for your patience and for helping us bring this security issue to our attention.

Best regards,

Log in to reply.