Joomla 3 Security Patch for SP Page Builder 1.0.2 release notes - JoomShaper

Fixed

  • Fixed an authorized SQL injection vulnerability in article and module save operations caused by insufficient input validation of database identifiers.
  • Fixed dynamic content filter XSS issue
  • Fixed an authorization issue in the Media Manager that allowed users with editing permissions to rename files outside the intended media directories.
  • Fixed a permission issue when creating or updating menu items through SP Page Builder, ensuring the required Joomla menu permissions are properly enforced.
  • Fixed an issue in the Media Manager that allowed users with author-level permissions to upload files to unintended directories within the site.
This isn’t the newest version. See what’s new in 1.0.3.