Urgent Security Issue: Malicious PHP Files Found In SP Page Builder Directories - Question | JoomShaper

Urgent Security Issue: Malicious PHP Files Found In SP Page Builder Directories

H

Hans

SP Page Builder 2 weeks ago

Dear JoomShaper Support,

I am contacting you regarding a serious security issue on my Joomla website.

I had completely removed my previous website, including all existing files, and started again with a fresh installation of Joomla 6. I then installed the latest available versions of Helix Ultimate and SP Page Builder Pro.

Despite this clean installation, my hosting provider has now detected a large number of malicious PHP files. Most of them were found in directories belonging to SP Page Builder, particularly:

/www/media/comsppagebuilder/assets/iconfont/.../fonts/ /www/tmp/builderCustomIcon.../fonts/

The detected files include names such as:

backdoor.PHP uploader.PHP cmd.PHP rce_*.PHP fm.php simple.PHP mini.PHP Various randomly named .php, .php3, .php4, .php5, .php7, .phtml, .pht and .phar files

I have attached the complete list provided by my hosting provider.

Because this was a completely fresh Joomla 6 installation using the latest versions of Helix Ultimate and SP Page Builder Pro, I am very concerned that an upload function or another vulnerability in SP Page Builder may have been exploited.

Could you please investigate this urgently and let me know:

Whether this is a known vulnerability in SP Page Builder Pro or Helix Ultimate. Whether the latest releases are fully secure and compatible with Joomla 6. How attackers could have uploaded executable PHP files into these icon-font and temporary directories. Which files and directories I should remove or replace. Whether I need to reinstall the complete website again. Which permissions or server rules I should apply to prevent PHP files from being executed in these directories. Whether you need any log files, file samples, timestamps or additional information from my hosting provider.

Please treat this as an urgent security matter. I would appreciate a detailed investigation rather than only instructions to delete the reported files, as I need to identify and close the original point of entry.

1
1 Answers
Paul Frankowski
Paul Frankowski
Accepted Answer
Senior Staff 2 weeks ago #231620

Hi Hans,

Probably you had old version of SPPB and that's why intruders came.

Read guide: https://www.joomshaper.com/documentation/sp-page-builder/troubleshooting#how-to-clean-an-infected-joomla-4x-6x-site

Follow steps (1-7) and next (1-4) to fix and improve site security.

In case of... I can help to clean it using our tool.


after all install firewall component (free/pro), it will be your last defence. In those times it's must have.

0