PT-2026-79836 · Joomla · Page Builder Ck
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Page Builder CK versions prior to 3.6.5
Description
The Joomla extension Page Builder CK contains a second-order SQL injection flaw. This occurs when the
loadStyles() function of the frontend page model constructs a query using previously stored data controlled by an attacker. When this stored value is subsequently loaded and concatenated into a SQL query, it allows for database read and modify operations, which could lead to administrative account takeover through the theft of sessions or credentials.Recommendations
Update to version 3.6.5.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Page Builder Ck