Potential Security Vulnerability In SP Page Builder 6.6.2 - Question | JoomShaper

Potential Security Vulnerability In SP Page Builder 6.6.2

MostElectrifyin

MostElectrifyin

SP Page Builder 1 week ago

Hi,

My hosting provider’s malware scanner recently detected eight suspicious files on a client’s website. All eight files were located in the following SP Page Builder directory:

/public_html/media/com_sppagebuilder/assets/iconfont/

At the time of detection, the site was already running:

SP Page Builder 6.6.2 Helix Ultimate 2.2.9

I removed the entire iconfont directory, and no additional malware alerts have been reported since.

Could you please evaluate this incident and consider performing a vulnerability check on SP Page Builder 6.6.2? If appropriate, please also update the existing security warning to clarify whether SP Page Builder 6 may be affected.

View the malware report screenshot

Thank you.

https://innercityski.org/malware_report_07122026.png https://innercityski.org/malware_report_07122026.png

0
5 Answers
J
jcalvert
Accepted Answer
1 week ago #229370

Hello,

I've been through this process of recovering from the very hack you are talking about, on multiple websites.

What's probably going on is that you applied the JoomShaper security updates to an infected website, so those injected files are still lying around, and there could be other files, and/or compromised files, and the Joomla database can also no longer be trusted.

When the hackers inject files, they follow up by trying to execute the files, for example .php files. They can also inject code directly into the Joomla database.

The best way to approach this problem is to restore the website from a backup that you know was taken prior to the hacking. Then you apply the security updates. Then you bring the site back online.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 week ago #229374

Yes, those infections (files) can be there hidden a days before you updated SPPB.

We published SPPB 6.2.2 last month, 15 June. And when you did update?


To clean site(s) use two tools mentioned in >> https://www.joomshaper.com/forum/question/45152#qa-answer-228412

Remember to keep Firewall installed, also after cleaning the site. In those "AI Hacker times" it's MUST have tool!

In the meatime, yes use FTP tool and delete all those folders and files from report.


Later, Create a ticket on your Hosting Support Center and ask them to scan your server using ClamAV / Imunify360 again.

0
J
jcalvert
Accepted Answer
1 week ago #229375

There are actually four distinct updates:

  • Page Builder Pro 6.6.2
  • Helix Framework ("Helix") 3.1.2
  • Helix Ajax 3.1.2
  • Helix Ultimate 2.2.9

All critical security updates to guard against live ongoing hacking activity.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 week ago #229378

You may have the latested version, but if hacker put a malware at least one file BEFORE update date, they can be hidden and wait for activation. Like spies.

Please use my tips, and mentioned tools etc.

And install FIREWALL component for danger times, if you want to sleep well.

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 week ago #229559
0