Unvalidated Email Routing Vulnerability in SP Property Joomla Extension
CVE-2026-78303

6.9MEDIUM

Key Information:

Vendor
CVE Published:
10 September 2026

What is CVE-2026-78303?

The unvalidated email routing vulnerability in the SP Property Joomla Extension allows malicious users to manipulate booking request emails. By exploiting hidden fields in the form, attackers can alter the email destination, resulting in unauthorized email delivery to unintended recipients. This flaw affects versions prior to 4.1.4 and highlights the importance of validating all user input to ensure secure email handling and application integrity.

Affected Version(s)

SP Property extension for Joomla 1.0.0-4.1.3

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.