Executive brief
SP Property is a real estate management extension for Joomla that handles property listings, agent profiles, and visitor interactions. The property booking and agent contact form endpoints fail to verify CSRF tokens, allowing attackers to forge requests from a victim's browser session to submit unauthorized bookings or contact form submissions without the victim's knowledge or consent.
Technical details
A CSRF (Cross-Site Request Forgery) vulnerability exists in the SP Property component's properties.booking and agents.sendmail endpoints. These endpoints process POST requests without validating Joomla's anti-CSRF session tokens, allowing an attacker to craft a malicious page that, when visited by an authenticated user, silently submits forged booking or contact requests. The vulnerability requires a victim to visit an attacker-controlled page while logged into a Joomla site with SP Property installed, but involves no complex interaction or social engineering beyond the visit itself. An attacker can abuse this to spam property bookings, submit false agent contact requests, or generate fraudulent leads, disrupting business operations and data integrity. The issue affects SP Property versions prior to 4.1.4.
Affected products
- JoomShaper SP Property < 4.1.4
Timeline
- 2026-09-10: disclosed