Executive brief
SP Property is a Joomla extension used to manage real estate listings, property galleries, and agent information on websites. The extension's gallery image management lacks proper access controls, allowing attackers to delete images with arbitrary paths and upload unverified file types without authorization. This could lead to defacement, data loss, and potential remote code execution through malicious file uploads.
Technical details
The vulnerability is a missing access control and CSRF token validation flaw in the gallery management controller of SP Property. The gallery management controller tasks do not implement proper authorization checks before processing file removal or upload operations, nor do they validate CSRF tokens. An attacker can invoke file removal actions with arbitrary path strings or upload unverified file types to the server. The attack vector is network-based and does not require prior authentication in certain contexts. Patches are available in version 4.1.4 and later.
Affected products
- JoomShaper SP Property < 4.1.4
Timeline
- 2026-09-10: disclosed