Bootstrap Version In SP Pagebuilder 6.2.1 - Question | JoomShaper

Bootstrap Version In SP Pagebuilder 6.2.1

UG

Uwe Geuder

SP Page Builder 1 month ago

Hello, a penetration test was carried out on our website, and the results show that in SP Page Builder the bootstrap version 3.4.1, which is outdated, is being used. Could you please let me know whether an upgrade to version 5.3.8 or newer is planned and when this will take place?

Could you please briefly confirm that version 3.4.1 used in SP Page Builder does not pose a vulnerability in terms of unauthorized access?

Thanks

0
8 Answers
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 month ago #212236

Hi,

we cannot fully confirm that, becuase bootstrap that was used inside SPPB is deeply customized (is not 1:1), there was separate forum topic where @Toufiq and @Atick explained that. In big short, there are only small parts of BT 3.x.

And online testers just search patterns like version number, without thinking like we humans.

Besides, you asked about the same 2 weeks ago.

0
UG
Uwe Geuder
Accepted Answer
1 month ago #212237

No I didn´ask the same two weeks ago. My central question is whether you can classify the software as safe: "Could you please briefly confirm that version 3.4.1 used in SP Page Builder does not pose a vulnerability in terms of unauthorized access?"

f you could confirm this for me, your software would be accepted.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 month ago #212257

I have to wait with full confirmation till Friday. Please remind me at the morning that day. We both have the same Time Zone.

But as I know, thru current script attact is not possible.

0
UG
Uwe Geuder
Accepted Answer
1 month ago #212270

Thanks, till Friday.

0
UG
Uwe Geuder
Accepted Answer
1 month ago #212631

Good morning, you asked me on Wednesday to remind you about making a specific statement on the topic of ‘script attack.’ Thank you for your feedback.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 month ago #212632

Yes, I remember , I also wait for respond.

0
PW
Paddy Wanless
Accepted Answer
3 weeks ago #214542

Hi,

I'm also wondering if there is an update to this question?

Our website(s) have also failed a penetration test due to this issue.

Thanks in advance for any updates,

Paddy

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 3 weeks ago #214547

As I know those old "patterns" that left shouldn't be problematic if we talk about security. But team is trying to remove most of them.

0