Server Side Template Injection Issue On SP Page Builder - Question | JoomShaper
Black Friday sale is live with flat 50% OFF. Sale ends soon! Grab your deal now!

Server Side Template Injection Issue On SP Page Builder

JS

James Lowell Sambadoo

SP Page Builder 3 years ago

Hi i did a scan on getastra.com after updating the sp page builder to the latest version 3.8.5 and found some issue with Server Side Template Injection issue:

/components/com_sppagebuilder/assets/css/sppagebuilder.css?f53ba91a9cc92bb2348e4eab5b1ff3a1=%3C%25%3D+foobar+%25%3E

/components/com_sppagebuilder/assets/css/font-awesome-v4-shims.css?f53ba91a9cc92bb2348e4eab5b1ff3a1=%3C%25%3D+foobar+%25%3E

/components/com_sppagebuilder/assets/css/font-awesome-5.min.css?f53ba91a9cc92bb2348e4eab5b1ff3a1=%3C%25%3D+foobar+%25%3E

Report: Details of Vulnerability Server Side Template Injection (SSTI) occurs when user input is directly embedded into the template without any proper sanitization, a hacker can use this vulnerability to inject malicious code and try to achieve remote code execution.

Suggested Fixes Always use proper functions provided by the template engine to insert data, if that is not possible try to sanitize user input as efficiently as possible.

How can I fix this without breaking the template?

0
2 Answers
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 3 years ago #60699

Hi James,

as I see all those files are loaded from component, not template folder.

007, I will ask our "Q" to check and solve it somehow in upcoming updates. Thanks.

0
JS
James Lowell Sambadoo
Accepted Answer
3 years ago #60701

Hi,

Thank for reply and waiting for the update.

0