Executive brief
Joomla's Page Builder CK extension is a page design tool that allows administrators to build website pages using a drag-and-drop interface. The extension contains a second-order SQL injection vulnerability in its page styling functionality that could allow an attacker with administrative access to execute arbitrary database queries, potentially leading to data theft or unauthorized modification of site content.
Technical details
The vulnerability is a second-order SQL injection flaw located in the loadStyles method of the frontend page model in Page Builder CK versions before 3.6.5. The vulnerability stems from insufficient input sanitization when processing page styling data. An attacker with authenticated administrator access can inject malicious SQL payloads that are stored and later executed when the styles are loaded, allowing arbitrary database queries to be run. The attack requires administrator-level access to the Joomla extension, limiting the immediate exposure but creating a significant risk for sites with compromised or malicious administrators.
Affected products
- JoomlaCK Page Builder CK before 3.6.5
Timeline
- 2026-08-24: disclosed