Executive brief
Quix Page Builder Pro, a popular drag-and-drop design tool for Joomla websites, contains a security flaw that can leak internal system information. An attacker can trigger specific errors that reveal technical details about the website's configuration or server environment. This information could potentially be used to plan more sophisticated attacks against the site.
Technical details
The Quix Page Builder Pro extension for Joomla (versions 1.0 through 6.2.0) is vulnerable to CWE-200 (Information Exposure). The vulnerability exists within the AJAX handler component, which fails to properly sanitize or suppress error messages. When an exception occurs during an AJAX request, the system returns raw exception data in the response. A remote, unauthenticated attacker can exploit this by sending crafted requests to trigger these exceptions, potentially revealing sensitive system information, file paths, or configuration details. The issue was reported by the Joomla! Project with a CVSS 4.0 score of 6.9.
Affected products
- ThemeXpert Quix Page Builder Pro extension for Joomla 1.0-6.2.0
Timeline
- 2026-07-20: advisory: CVE published by the Joomla! Project