Joomla 扩展 - joomshaper.com - SP Property < 4.1.4 中属性搜索与地图筛选功能存在未经认证的 SQL 注入漏洞 在 SP Property 4.1.4 之前版本中,属性搜索和列表的查询构建器通过直接拼接原始请求参数(如 zipcode、排序字段、价格区间下拉框、房屋面积区间下拉框等)到 SQL 字符串中,而未进行引号转义或类型转换,用于构建 WHERE 和 ORDER BY 子句。未经认证的远程攻击者可利用该漏洞执行布尔型或时间型盲 SQL 注入,从而从数据库中提取敏感数
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| joomshaper.com | SP Property extension for Joomla | 1.0.0-4.1.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78302 | 8.6 HIGH | Joomla Extension - joomshaper.com - Unauthenticated Cross-Site Scripting (XSS) via Unescap |
| CVE-2026-78083 | 7.1 HIGH | Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking an |
| CVE-2026-78303 | 6.9 MEDIUM | Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in B |
| CVE-2026-78084 | 6.9 MEDIUM | Joomla Extension - joomshaper.com - Missing Access Control in Gallery Image Management in |
| CVE-2026-78085 | 6.9 MEDIUM | Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Prope |
No comments yet