ZeroHour

CVE-2026-78083

niche

Missing CSRF protection in JoomShaper SP Property booking and contact endpoints

CVSS 4.0
7.1 high
EPSS
Published
()
Modified
AI analysis

SP Property, a real-estate listing component for Joomla from JoomShaper, versions before 4.1.4, processed POST requests on its visitor booking (properties.booking) and agent contact form (agents.sendmail) endpoints without verifying Joomla session anti-CSRF tokens (CWE-352). An attacker can host a page or link that induces a visitor's or logged-in user's browser to silently submit forged POST requests to these endpoints; because no token check is performed, the requests are accepted regardless of origin. The practical impact is rated high for integrity: an attacker can inject fraudulent booking submissions or trigger contact/email sends through the site's mail (e.g., spam or spoofed messages to agents), though no confidentiality impact is expected. Any Joomla site running SP Property prior to 4.1.4 is affected. There is currently no known exploitation, no public proof-of-concept, and the issue is not in CISA's KEV; a fix was released in SP Property 4.1.4.

What to do: Upgrade SP Property to 4.1.4 or later, available from JoomShaper. Until updated, there is no built-in configuration mitigation, so review site logs for unexpected or forged POST submissions to the properties.booking and agents.sendmail endpoints and consider WAF rules or Joomla's CAPTCHA/token-hardening options as partial mitigations.

Affected
JoomShaper (joomshaper.com) SP Property (Joomla extension)all versions prior to 4.1.4 (< 4.1.4)
Estimated exposure
nichelikely thousands of sites at most (no published install counts; niche paid component within the ~1-2M-site Joomla ecosystem) — Joomla does not publish per-extension active-install figures and SP Property is a paid, specialized real-estate component from JoomShaper, so only a small subset of the roughly 1-2 million Joomla sites is plausibly affected; this is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Joomla Extension - joomshaper.com - Missing CSRF Token Verification in Property Booking and Agent Contact Endpoints in SP Property < 4.1.4 - The visitor booking (properties.booking) and agent contact form submission (agents.sendmail) endpoints processed POST requests without verifying Joomla session anti-CSRF tokens.

Ecosystems
Joomla
Weakness
CWE-352
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.