B3NCLOUD ARTICLE INTELLIGENCE

ARTICLEVIEW

Zurück zu News

CVE-2026-48909 - Joomla Extension - joomshaper.com - PHP Object injection in SP LMS extension for Joomla < 4.1.4

CVE ID :CVE-2026-48909 Published : June 20, 2026, 11:56 a.m. | 1 hour, 13 minutes ago Description :SP LMS (com_splms) < 4.1.4 by JoomShaper deserializes user-controlled cookie data without validation, enabling an unauthenticated remote attacker to execute arbitrary code on the server. ...

Original-Artikel öffnen Zurück zur Übersicht