Access Control Flaw in SP Property by JoomShaper
CVE-2026-78084
6.9MEDIUM
What is CVE-2026-78084?
The SP Property extension by JoomShaper suffers from a missing access control vulnerability in its gallery image management features. This issue allows authenticated users to execute file removal actions without proper authorization checks or CSRF token validation. Consequently, an attacker could potentially manipulate file paths to delete arbitrary files or upload malicious file types, posing significant risks to the integrity of the website.
Affected Version(s)
SP Property extension for Joomla 1.0.0-4.1.3
