Thank you for your response and for forwarding both repositories to your development teams. We understand that JoomShaper cannot officially recommend or endorse third-party modifications before the code and its compatibility implications have been reviewed.
We also agree that sensitive security findings, reproduction steps, and proof-of-concept details should not be published in the public forum. We have therefore deliberately limited the information in our public repositories to defensive hardening, installation, restoration, and operational guidance. Any further sensitive findings can be provided through your hidden content box or another appropriate private security channel.
During our investigation, we identified an additional operational problem involving database entries left behind by the affected asset and custom-icon processes. On installations with many accumulated records, these stale or orphaned asset entries can negatively affect performance and slow down the website and administrator interface.
We have therefore also created a cleanup script for these database entries. An updated version of our package will include this cleanup functionality, together with the existing upload hardening, installer, backup, checksum-verification, and restore/deinstaller functionality. latest Version will be pushed in the next view hours.
The current repositories are: (we do not post on github normaly as all Serious-DEV Teams should use there own gitlabs)
Main hardening package:
https://github.com/konzeptplus-gmbh/SPPB-Upload-Custom-Icon-Hardening
Restore and deinstaller package:
https://github.com/konzeptplus-gmbh/SPPB-Upload-Custom-Icon-Hardening-Restore
Users who require the installable ZIP files can open the relevant repository, select “Releases,” and download the ZIP package attached to the latest release. The repositories also contain the compatibility information, installation instructions, checksums, and technical documentation.
We would also like to inform you that, after beginning a more extensive review of SP Page Builder and the related framework code, we identified several additional security-relevant concerns. We will not publish these findings publicly because doing so could unnecessarily expose Joomla installations before the issues have been reviewed and corrected.
However, the number and nature of the issues we encountered indicate that the relevant upload, archive, asset, AJAX, authorization, file-handling, and framework code should receive a broader security review rather than only a narrowly scoped correction for the originally reported endpoint.
Please ask your development and security teams to review the surrounding code paths carefully. We are prepared to provide the additional technical findings privately, including affected files, conditions, and evidence, through an appropriate confidential channel.
Our intention is not to compete with or replace the official product. We created these packages because we are responsible for several hundred customer websites and needed an immediately deployable, reversible mitigation while waiting for a complete upstream solution.
We appreciate your responsible response and look forward to receiving confirmation regarding:
- Which official SP Page Builder version fully addresses the original vulnerability.
- Whether the upload and archive-handling implementation has been comprehensively hardened.
- Whether the related asset database records and cleanup requirements will be addressed.
- Whether the surrounding framework and AJAX code will receive an extended security audit.
- How we should securely submit the additional non-public findings to your team.
Thank you again for reviewing our work and for treating this matter seriously