CyberRota Analysis
AI-GeneratedThe SP Page Builder extension for Joomla versions prior to 6.7.1 contains a critical vulnerability due to a hardcoded secret, enabling unauthenticated attackers to exploit the mail relay functionality and forge the sender's email address in forms. This could lead to phishing attacks or the distribution of malicious content under the guise of legitimate communications. Joomla site administrators and developers using this extension should prioritize immediate updates to mitigate the risk of exploitation.
Original NVD Description
Joomla Extension - joomshaper.com - Unauthenticated mail relay via a hardcoded, product-wide secret in SP Page Builder < 6.7.1 - A hardcoded secret allowed attackers to forge the mail from address of forms.