Active SQL Injection Vulnerability - Question | JoomShaper

is live, now with multi-currency selling.

Active SQL Injection Vulnerability

K

komir

SP Page Builder 1 month ago

Hello,

I use mysites.guru to maintain my websites, and I have just received a critical security warning regarding SP Page Builder v6.7.1.

According to the security alert, version 6.7.1 contains an active, unauthenticated SQL injection vulnerability in the front-end article loading endpoint (articles.loadMoreArticles), which is reportedly being actively exploited in the wild.

Could you please provide an estimated timeframe for when version or patch will be officially released and available for download?

Thank you for your prompt response regarding this critical issue.

Best regards

0
9 Answers
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 month ago #231532

Yes, it should be today, I hope very soon.

If somebody needs fixed file (sooner) I put inside "Hidden Content" , look below

0
E8
Easy Connect 83
Accepted Answer
1 month ago #231535

Hello, I don't see any hidden content in your post to access the patch.

0
E8
Easy Connect 83
Accepted Answer
1 month ago #231530

Hello, I’m in the same situation. I also use the MySites.guru service.

I reported it to them yesterday.

They replied saying they would offer an update this morning...

0
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 1 month ago #231536

Becuase it wasn't your topic.

Shared on your e-mail already

0
E8
Easy Connect 83
Accepted Answer
1 month ago #231537

Thanks

0
MiBa
MiBa
Accepted Answer
1 month ago #231562

Wouldn't it be advisable to publish the patch in the Downloads section for all until version 6.8.0 is released, and create a locked forum topic with a link?

1
D
David Forés
Accepted Answer
1 month ago #231565

The logical thing would have been for them to release version 6.7.2 to fix the critical vulnerability, and then release 6.8.0 once it was ready with the rest of the fixes and improvements.

2
C
copycat
Accepted Answer
1 month ago #231569

Mysites Guru was on vacation from July 30 to August 10, and we had about ten days of peace — all of us in the Joomla community. Now we’re back to daily patching, updates, and so on. Yesterday, I posted on JoomShaper’s Facebook page warning that the guy is back from vacation and that we’re starting again as before.

1
R
Rvdzande
Accepted Answer
1 month ago #231617

Well you could also turn it around.

If a crime gets commited and there is no police to do an arrest? Should we than still not qualify it as a crime?

I have no affiliation or relation with MySites.Guru but I think this site and htproject are doing a good job. They are reporting things to keep a site safe. If they report or not doesnt change anything to their price or service, so I don't see the issue here. The issue is in the software flaws (which will always be happening because humans just make mistakes).

0