JoomShaper SP Page Builder Unauthenticated File Upload Remote Code Execution Exploit

CVE-2026-48908 affects JoomShaper SP Page Builder versions 6.6.1 and earlier. The asset.uploadCustomIcon task accepts an icon-font ZIP without authentication or a CSRF token. The module sends a valid multipart icon-font package in the custom_icon field. The vulnerable component extracts the archive below media/com_sppagebuilder/assets/iconfont/name/, a location normally served by the Joomla web server. The archive contains a randomly named, token-guarded PHP file in the fonts directory. The module first requests that file with a harmless marker to distinguish file write from server-side PHP execution. It then uses the same endpoint to deliver the selected Linux Impact agent. Successful execution depends on the target web server allowing PHP execution for the extracted media directory. If the upload succeeds but PHP is not executed there, the target is file-write vulnerable but is not confirmed as remote code execution by this module. The agent runs with the privileges of the Joomla/PHP service account, commonly www-data on Linux Apache deployments. No administrator credentials are required.
Exploit Platform
Product Name