1 article with this tag
SP Page Builder for Joomla (by JoomShaper) ≤ 6.6.1 has an unauthenticated arbitrary file upload → RCE (CVSS 10.0, in CISA KEV). The custom-icon upload reportedly ran no auth or type validation. The real fix is updating to 6.6.2, plus a compromise check (rogue admins, web shells). The durable defense is designing out the 'unauthenticated upload → RCE' pattern.