Active SQL Injection Vulnerability - Question | JoomShaper

Active SQL Injection Vulnerability

K

komir

SP Page Builder 1 hour ago

Hello,

I use mysites.guru to maintain my websites, and I have just received a critical security warning regarding SP Page Builder v6.7.1.

According to the security alert, version 6.7.1 contains an active, unauthenticated SQL injection vulnerability in the front-end article loading endpoint (articles.loadMoreArticles), which is reportedly being actively exploited in the wild.

Could you please provide an estimated timeframe for when version or patch will be officially released and available for download?

Thank you for your prompt response regarding this critical issue.

Best regards

0
5 Answers
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 hour ago #231532

Yes, it should be today, I hope very soon.

If somebody needs fixed file (sooner) I put inside "Hidden Content" , look below

0
E8
Easy Connect 83
Accepted Answer
40 minutes ago #231535

Hello, I don't see any hidden content in your post to access the patch.

0
E8
Easy Connect 83
Accepted Answer
1 hour ago #231530

Hello, I’m in the same situation. I also use the MySites.guru service.

I reported it to them yesterday.

They replied saying they would offer an update this morning...

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 31 minutes ago #231536

Becuase it wasn't your topic.

Shared on your e-mail already

0
E8
Easy Connect 83
Accepted Answer
24 minutes ago #231537

Thanks

0