Executive brief
SP Page Builder is a popular Joomla page builder extension used to create and design website pages via drag-and-drop. A vulnerability in the media rename function allows attackers to rename arbitrary files on the server, including critical configuration files, which could take the website offline or enable further compromise of the installation.
Technical details
The media rename task in SP Page Builder (versions 4.0.0 to 6.9.0) fails to implement proper directory boundary checks and validates only that either a media record exists or the path is present in the database, without verifying they match. The STR input filter leaves path traversal sequences intact, allowing an attacker to pair any valid media identifier with an unrelated filesystem path and rename files outside the intended directory. An attacker could rename critical files such as configuration.php to disable the site. The vulnerability requires authentication and access to the media rename functionality, but no patch information is currently available.
Affected products
- JoomShaper SP Page Builder 4.0.0 to 6.9.0
Timeline
- 2026-09-14: disclosed