Junglewise Threat Intelligence

CVE-2026-78303: JoomShaper SP Property unvalidated email destination in booking forms

CVE-2026-78303 · Severity: info · Published 2026-09-10

Technologies: JoomShaper SP Property. Vendors: JoomShaper.

Executive brief

SP Property is a Joomla extension for managing real estate properties, agents, and visitor booking requests. The extension previously allowed attackers to manipulate email routing by submitting unauthorized hidden form fields, potentially redirecting booking inquiries to attacker-controlled addresses instead of legitimate property managers or agents.

Technical details

The vulnerability exists in SP Property's booking request and contact forms, which relied on client-submitted hidden form fields to determine the email recipient address. An attacker could intercept and modify these fields before submission, causing booking inquiries to be sent to arbitrary email addresses. This is a form manipulation and unvalidated redirect issue. The attack requires network access to the form and no authentication, but does require the attacker to interact with the form submission process. The fix is available in SP Property version 4.1.4 and later, which should validate and enforce email destinations server-side.

Affected products

  • JoomShaper SP Property < 4.1.4

Timeline

  • 2026-09-10: disclosed

References

Related threats