CVE-2026-78303: Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4
Published Sep 10, 2026
·Updated
Joomla Extension - joomshaper.com - Unvalidated Email Destination & Form Manipulation in Booking Requests in SP Property < 4.1.4 - Booking inquiries previously relied on client-submitted hidden fields for recipient routing, allowing potential email manipulation.
Affected Software
1 affected component
SP Property<4.1.4
Event History
Sep 10, 2026
CVE Published
via MITRE·09:56 AM
Data Sourced
via MITRE·09:56 AM
DescriptionWeakness
Frequently Asked Questions
1
Who is exposed to this issue?
Sites using SP Property versions earlier than 4.1.4 with booking inquiries are exposed, because booking recipient routing relied on client-submitted hidden fields.
2
What does an attacker need to exploit it?
An attacker would need to submit or manipulate a booking inquiry so that the client-submitted hidden fields used for recipient routing are altered.
3
What should be done to remediate the issue?
Upgrade SP Property to version 4.1.4 or later.