Menu Failure After Update - Question | JoomShaper

Menu Failure After Update

J

Jürgen J. Fischer

Helix Framework 2 weeks ago

Hi, I have the next problem with Menü after update. Menu is not working correct, and I have "< ... "> in menu. I seems that active menu items does the failure.

Before Update to new helix everything was ok!

How can I solve this. I have the same problem on other sites, also after update to helix newest version.

You see it in https://erlebnisgasthof-krieger.de/

0
7 Answers
Ziaul Kabir
Ziaul Kabir
Accepted Answer
Support Agent 2 weeks ago #230174

Hello,

Thanks for reaching out to us. Could you please share temporary administrator access to your Joomla backend? You can provide the credentials securely in the hidden content section. Also, please take a full backup of your site before we make any changes.

Once I have access, I’ll investigate further and see what’s causing the issue. Let me know once you’ve shared the details!

Best regards,

0
Rashida Rahman
Rashida Rahman
Accepted Answer
Support Agent 2 weeks ago #230175

Hi,

Thanks for reaching out.

I checked your site and noticed that the menu contains an injected JavaScript snippet, which is causing the broken HTML to appear in the active menu items. This is not related to the Helix update itself but indicates that malicious code has been injected into your menu.

Please check your menu items in Menus → Menu Items, especially the active menu item, for any unexpected script tags or other injected code. You should also perform a malware scan on your site, verify that there are no unauthorized administrator accounts, and consider installing a reputable firewall/security extension to help detect and prevent future attacks.

Once the malicious code has been removed, the menu should display correctly again.

Best regards,

0
J
Jürgen J. Fischer
Accepted Answer
2 weeks ago #230188

Hi and thank you

I found this injected snippet. But I have the same issue on 6 websites, and the snippet seems to come with update helix or sp pagebuilder. Every Site was ok, and after update the injected code is activ.

Last month we had a lot of problems with hack of sp pagebuilder/helix and I am not sure, if the new problem comes also from helix.

So what can we do?

Thank You

0
J
Jürgen J. Fischer
Accepted Answer
17 hours ago #231438

Hi Yes I could solve the problem with extension muruguard from github. All injections deleted, menu work now fine on all pages.

SOLVED

0
Rashida Rahman
Rashida Rahman
Accepted Answer
Support Agent 3 days ago #231361

Hello,

We haven’t heard back from you regarding this issue. Could you please confirm if everything is working fine now? If so, kindly accept the most helpful answer to close the post.

Best regards,

0
Rashida Rahman
Rashida Rahman
Accepted Answer
Support Agent 14 hours ago #231456

Hi,

Thanks for the response. I'm glad that your issue has been solved now:)

Have a nice day!

0
Rashida Rahman
Rashida Rahman
Accepted Answer
Support Agent 2 weeks ago #230219

Hi,

Thanks for the follow-up.

The injected snippet is not part of either the Helix Ultimate or SP Page Builder update. We have not identified any such code in our released packages.

If the same injected code is present on multiple websites, it is more likely that they were compromised through another attack vector (for example, outdated extensions, compromised administrator credentials, or the previous security incident) before or during the update. Maybe the update itself simply made the already injected code visible.

We recommend the following:

  • Perform a full malware scan on each affected website.
  • Check for any unauthorized Super User accounts.
  • Update Joomla and all third-party extensions to their latest versions.
  • Change all administrator, hosting, FTP, and database passwords.
  • Install a reputable firewall/security extension to help detect and prevent future attacks.

If you continue to find the same injected code after completely cleaning a site, please provide temporary Joomla administrator access and FTP access. We'll be happy to investigate further to determine whether the code is still being injected and, if so, from where.

Best regards,

0