[Locked] ๐’๐ ๐๐š๐ ๐ž ๐๐ฎ๐ข๐ฅ๐๐ž๐ซ ๐’๐ž๐œ๐ฎ๐ซ๐ข๐ญ๐ฒ ๐๐š๐ญ๐œ๐ก ๐š๐ง๐ ๐Œ๐š๐ง๐ฎ๐š๐ฅ ๐…๐ข๐ฑ ๐ƒ๐ž๐ญ๐š๐ข๐ฅ๐ฌ - Question | JoomShaper

Celebrate JoomShaper's Sweet 16 with Flat 35% OFF!

28 Answers
C
Chriss
Accepted Answer
2 days ago #226392

WOW, ONE WEEK LATER!

0
Ofi Khan
Ofi Khan
Accepted Answer
Support Agent 2 days ago #226396

Hello Chriss

Apology for the delay. We heard your voice and felt the necessity for a free patch. If you have an active SP Page Builder subscription, then you need to update the version to 6.6.2. No further action needed.

If you do not have a subscription, only then use the patch. Just the change the file contents of components/com_sppagebuilder/controllers/asset.php and the site will be safe again.

Thanks for keeping your trust in us.

Best regards

0
D
David Forรฉs
Accepted Answer
2 days ago #226400

Just to clarify, when you say that โ€œno further action is needed,โ€ you should specify that this applies only if the website hasnโ€™t been hacked. In that case, itโ€™s true that simply updating the version would be enough.

But if the site has been hacked, no matter how much you update SP Page Builder, the attackers already have complete control over your site and have likely left several hidden backdoors through which they can re-enter. In this case, there is indeed a LOT of work to be done.

0
Toufiq
Toufiq
Accepted Answer
Senior Staff 2 days ago #226424

Thank you for pointing this out. You are right, we should clarify that no further action is needed applies only to websites that were not compromised and have simply updated to the patched version.

If a website was already compromised before applying the update, additional security checks are required, as updating only fixes the vulnerability but does not automatically remove any existing malicious files or changes.

We appreciate your clarification and will make sure our communication is clearer on this point.

0
C
Chriss
Accepted Answer
2 days ago #226402

โ€œThanks for continuing to trust us.โ€

No, you've lost that trust. Once again, your help is way too late! The honest answer would have been to delete everything, restore the backup, and buy the update. Don't just slap a file together a week later! Sticking with SP PageBuilder is a mistake!

0
Toufiq
Toufiq
Accepted Answer
Senior Staff 2 days ago #226422

Weโ€™re really sorry for the frustration and inconvenience this has caused. We understand your concern, and this is not the experience we want you to have.

The fix was already included in the v6.2.2 patch release. The file we shared separately is the same fixed file for users who need a quick manual solution without going through the full update process.

We truly appreciate your patience and feedback. Weโ€™ll continue working to improve our release and support process.

0
Anke Sauer
Anke Sauer
Accepted Answer
2 days ago #226405

Yes, I have to agree with that. Iโ€™m now dealing with a huge mess across many of my clientsโ€™ websites. And as is often the case with clients, they didnโ€™t necessarily back up their data after their last updates. I canโ€™t even bill them for my work while Iโ€™m sitting here trying to get everything back on track. This really shouldnโ€™t happenโ€”after all, theyโ€™re putting a lot of money into this, not to mention their trust. My clients trust me, too, and now I have to explain to them why the sites arenโ€™t working anymore. Thatโ€™s it, then. Thanks a lot for that.

0
C
Chriss
Accepted Answer
2 days ago #226407

I can only recommend rebuilding your website and uninstalling SP PageBuilder as soon as possible. Iโ€™ve taken down 6 sites so far, and as you can see here, the effort has totally paid off. The last two are going down now!

0
Toufiq
Toufiq
Accepted Answer
Senior Staff 2 days ago #226423

We sincerely apologize for the trouble and frustration this has caused. We understand how difficult this situation is when managing multiple client websites, and we truly regret the inconvenience.

The fix has already been included in the v6.2.2 patch update. We also shared the specific fixed file separately to help affected users resolve the issue faster.

If any websites are still having issues, please share the details with us. Our team will do our best to help you get everything back on track.

Thank you for your feedback. We take this seriously and will continue improving our release process.

0
A
ANT
Accepted Answer
2 days ago #226411

Thanks for all. I have an old j3 and sppb 3.8.10 (I know) is this normal that asset.php does not exist ?

0
Toufiq
Toufiq
Accepted Answer
Senior Staff 2 days ago #226420

If you are using Page Builder 3, you donโ€™t need to worry about this security update.

0
A
ANT
Accepted Answer
1 day ago #226430

the mail sent today was about joomla 3 and sppb3

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 day ago #226462

@Ant, answer is already here: https://www.joomshaper.com/forum/question/45163

0
ML
Mike Lawson
Accepted Answer
1 day ago #226436

Figured Id take a break from fixing my client's hacked websites and chime in on the matter.

Ever considered offering credits to your loyal subscribers? Constantly apologizing over and over is more insulting than it is comforting.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 day ago #226443

@Chris, not really! This is free path for webmasters without active SPPB subsctiption.

And as you may know, not all developers do that.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 day ago #226444

It was general info that you are using old versions on your own risk. We don't update and improve extensions for J3 anymore.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 day ago #226445

What do you mean saying "credits" ? as I know every software had or will have security holes. Even big ones from Top 100, Windows or Android included!. In this comparison, we are a small "player". And the Joomla market share is only getting smaller every year, not growing :/ Such security problems, therefore, are painful for both sides. Believe me, I'd rather answer the question โ€œHow do I change the button color?โ€ 100 times than read about a website being hackedโ€”whether it's because of us or for some other reason.


@Mike, We talk about that face-to-face on Joomla Day 2026, if you will be there.

0
ML
Mike Lawson
Accepted Answer
1 day ago #226473

Credits as in crediting money people pay you for using your product that is completely compromised. Ive never encountered a Joomla plugin or component with such a gaping security flaw..until now.

Anyways, any idea how I can stop my website from being hacked?? Something is hacking my root folder and adding .html files and folders...and erasing my .htaccess file. I have V6.6.2 installed and Im still getting hacked!

0
AM
Ahmad Moussa
Accepted Answer
1 day ago #226455

Hello Toufiq, please is this applied on SP Page Builder 3 on Joomla 3 site?

0
martin
martin
Accepted Answer
1 day ago #226459

thatโ€™s a good question

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 day ago #226461

SPPB 3.8.10 don't have upload custom Icon feature, so found SPPB security problem don't effect 3.x version. Full answer is already here: https://www.joomshaper.com/forum/question/45163ย  and also here in the middle: https://www.joomshaper.com/forum/question/45152

@Ahmad, @Martin, @Ant, @Indi

0
AM
Ahmad Moussa
Accepted Answer
1 day ago #226463

Thank you Paul for the information.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 day ago #226504

@Mike

For example, serious vulnerabilities are regularly discovered in the MS Office suite. The last 5 years (the period from 2021 to 2026) have been a time when Microsoft had to deal with both so-called zero-days (vulnerabilities actively exploited by hackers before a patch is released) and a wave of clever bypasses of existing security measures. But somehow I don't recall Microsoft giving users anything in return to customers for their losses. Except, at most, price hikes for subsequent versions.


Check main topic (https://www.joomshaper.com/forum/question/45152) where we all (as community) add many useful tips every single day to help each other. If your infection returns it means that there is hidden a file on your server that allows that. Read what @Yves Lacroix wrote today, at the bottom (from shared link).

0
P
point
Accepted Answer
1 day ago #226517

Hello,

after the recent security announcement regarding SP Page Builder v6.6.2 and the affected file:

components/com_sppagebuilder/controllers/asset.php

I checked several of our Joomla websites that use SP Page Builder.

The only installation where I found this file was the one running SP Page Builder v3.7.14. On that website, the file existed at the mentioned path, so I replaced it with the patched version from the provided GitHub gist.

On the other SP Page Builder installations I checked, using different 3.x versions, this file does not exist at all.

My questions are:

  1. Is this security issue only related to SP Page Builder v6.6.2 and later, or can it also affect older SP Page Builder 3.x versions?
  2. If the file components/com_sppagebuilder/controllers/asset.php does not exist on a website, does that mean the website is not affected by this specific vulnerability?
  3. Should we manually add this patched file to older installations where the file does not exist, or should the patch only be applied if the file is already present?
  4. Since I found the file only on the installation running v3.7.14, does that version require the patch?
  5. For websites running older SP Page Builder 3.x versions, is updating to the latest available 3.x version enough, or is there a separate security fix required?

We manage multiple Joomla websites using SP Page Builder and want to make sure all of them are properly secured.

Thank you.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 day ago #226522

@Point.

Let's be serious, using version 3.7 from Sep 2021, 5 years later is not the best idea. You should have at least SPPB v3.8.10 (may 2023) and firewall installed (anyway). Why you couldn't update it sooner?


  1. Yes. The fix we shared was for SPPB 5.x and SPPB 6.6.x only. In 6.6.2+ is already fixed.
  2. No
  3. Look (1)
  4. SPPB Pro 3.8.10 can still be downloaded from our website, please use it to update site(s).
  5. Scroll up, what I wrote yesterday here about SPPB 3.8.10. In general, yes.

If you have any other questions, feel free to ask.


Ask your hosting support: Does your server have account (website) isolation in place so that an infected site does not act as a gateway to another site on the same account?

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 day ago #226532

IMPORTANT, READ BEFORE POSTING // IMPORTANTE: Lร‰ELO ANTES DE PUBLICAR // WICHTIG โ€“ BITTE VOR DEM POSTEN LESEN // IMPORTANT, ร€ LIRE AVANT DE PUBLIER

The above fix file is only for SP Page Builder 5.x-6.6.1, if you still have SPPB 4.x or SPPB 3.x is not for you!

If you updated to SPPB 6.6.2+ you have it already.

0
P
Petra
Accepted Answer
21 hours ago #226605

Hi guys,

I installed 6.6.2 on a new site with Joomla 6.1.1 and template selixo (just template installation over fresh Joomla!) and when I want to use the articles addon, there is no way to select the category. Can you please check on your side and advise how to fix it? I tried installing 6.6.1 over it, but it did not help.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 21 hours ago #226609

@Petra, this topic is/was only about security !!!

Yes, we know about that issue. It will be fixed in next update.

Temporary it can be fixed by using file from older SPPB version. Here is short guide, next time NEW TOPIC !!!

Download any new quickstart (Kind or Nexio or older) and take this file: components\com_sppagebuilder\addons\articles\admin.php

OR

use older SPPB 6.6.0 and take this file from it: site\addons\articles\admin.php

Then using FTP upload & override that file: components\com_sppagebuilder\addons\articles\admin.php

that's all! you're welcome.

0
This topic is locked