SP Property - Unauthenticated SQL Injection - Question | JoomShaper

SP Property - Unauthenticated SQL Injection

SL

Sascha Langguth

Extension 1 week ago

The message "Plugin: SP Property Finder (com_spproperty) 4.1.3 and below - Unauthenticated SQL Injection (full database read, no fix yet)" appears in mySites.guru. Is there already an update for the component, or is one currently in development?

0
1 Answers
Ziaul Kabir
Ziaul Kabir
Accepted Answer
Support Agent 1 week ago #232257

Dear Sascha,

Thank you for bringing this to our attention.

We are aware of the reported unauthenticated SQL injection vulnerability affecting SP Property (com_spproperty) 4.1.3 and below. The issue has already been forwarded to our development team for investigation.

At the moment, we cannot confirm a publicly available fixed release yet. Our team is working on the issue, and we will provide an update as soon as a patched version is available.

Thank you for your patience and for helping us bring this security issue to our attention.

Best regards,

0