Every CMS can be hacked!!! Joomla and WordPress, it's time to wake up from the sweet dream.
If you are not expirenced webmaster do what I told you. It will be faster and better then spending hour(s) on cleaning site.
Then update:
- Template framework, we published all updated already.
- All extenstions (check one by one)
- Uninstall all extensions that you don't really use.
- Install Firewall component and scan site
- Ask hosting support to scan server as well.
Sign that template code was hacker, doesn't mean that template code was guilty! It doesn't work this way. Hole could be from one of many extensions that you (may) have. Only in last 6 weeks security holes were found in many extensions for Joomla.
And as you know Joomla 3.10.12 it's not supported by Joomla.org anymore, and may have security holes, some of them were fixed in Joomla 3.10.15. But then project was closed for obvious reasons. Joomla 6 or Joomla 5 core is more secured than Joomla 3 core.
Still, I understand that getting hacked—whether it's a website or a home or a car —isn't a pleasant experience.