Impact
The vulnerability is a path traversal flaw in the Gridbox Joomla extension’s image preview feature. The showImage action resolves a user-controlled path, passes it to an uploader helper that only verifies a matching prefix, and then returns the image. If image decoding fails, the request streams the file directly, permitting an attacker to read files located outside the configured images root that share the same prefix. The flaw is limited to Gridbox image file types, so the read primitive is restricted by file extension, but still permits disclosure of sensitive images or other files present in sibling directories.
Affected Systems
balbooa.com Gridbox extension for Joomla, versions earlier than 2.20.4.0. The affected component resolves paths relative to the default media root ‘images’ and may inadvertently expose files in directories such as ‘images-backup’.
Risk and Exploitability
The CVSS score is 6.3, indicating a medium severity vulnerability. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit the flaw via a remote web request to the showImage endpoint, using a crafted path that traverses to a sibling directory. The read primitive is constrained to Gridbox image types, limiting the scope of disclosure to those file extensions. Overall risk remains moderate, with a realistic possibility of exploitation over the web if the platform is publicly exposed.
OpenCVE Enrichment