Hi,
During routine security audits and log analysis, I identified what appears to be a critical security vulnerability in SP Page Builder (v6.1.1 and potentially older versions).
Under specific circumstances, this flaw could potentially allow malicious actors to bypass standard security checks and perform unauthorized actions on the server. Based on our recent server logs, it seems this vulnerability might already be targeted by automated bots in the wild, which could lead to severe site compromises.
To strictly practice Responsible Disclosure and avoid providing any actionable information to malicious actors reading this public forum, I have placed the exact nature of the flaw, the affected files, and the technical mechanics exclusively within the Hidden Content section of this ticket.
I have temporarily mitigated this on our infrastructure via ModSecurity rules blocking the endpoint, but an official patch is urgently needed. I can provide the Apache access logs and the malware samples privately upon request.
Please review the hidden details and escalate this to your security and development team as soon as possible.
Best regards.