Description
Joomla Extension - balbooa.com - CSRF in language installation feature Gridbox < 2.20.4.0 - PagesController uses a trait that validates the Joomla session token only when the HTTP method is POST. addLanguage does not require POST inside the action and reads url and zip through the generic request input. A GET request can therefore reach the action without the trait checking a token. The action still requires core.tools , but that is the victim’s permission check; it does not prove that the privileged user intended the request.
Published: 2026-10-08
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: Privilege escalation (inferred)
Action: Immediate Patch
AI Analysis

Impact

An attacker can exploit a cross‑site request forgery (CSRF) flaw in the Gridbox extension for Joomla. The addLanguage action accepts GET requests and reads a language pack URL and ZIP file from the query string without enforcing the Joomla session token, because the security trait that validates the token is applied only to POST methods. This allows an attacker to trigger the installation of an arbitrary language pack. Based on the description, it is inferred that an attacker could introduce malicious code into the site through a malicious language pack, potentially leading to unintended code execution or site compromise, though the CVE text does not explicitly confirm this outcome.

Affected Systems

All installations of balbooa.com’s Gridbox extension for Joomla with versions earlier than 2.20.4.0 are affected. The issue occurs in the PagesController trait used by the addLanguage function and applies to any deployment using those pre‑2.20.4.0 releases.

Risk and Exploitability

The CVSS base score of 8.7 indicates high severity. The attack can be performed over the network by sending a crafted GET request to the addLanguage endpoint. No EPSS score is available, so the current exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploits yet. However, sites with administrators granted the core.tools permission are at high risk, because the permission check is the only remaining safeguard and does not confirm the user’s intent.

Generated by OpenCVE AI on October 8, 2026 at 15:43 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Gridbox to version 2.20.4.0 or later.
  • If upgrading is not immediately possible, block GET requests to the addLanguage endpoint or disable the language installation feature entirely.
  • Ensure that the core.tools permission is granted only to trusted administrators and remove any unnecessary users from this group.
  • Add CSRF protection by validating the Joomla session token for all HTTP methods when accessing addLanguage, addressing CWE‑352.

Generated by OpenCVE AI on October 8, 2026 at 15:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
First Time appeared Balbooa.com
Balbooa.com gridbox Extension For Joomla
Vendors & Products Balbooa.com
Balbooa.com gridbox Extension For Joomla

Thu, 08 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Joomla Extension - balbooa.com - CSRF in language installation feature Gridbox < 2.20.4.0 - PagesController uses a trait that validates the Joomla session token only when the HTTP method is POST. addLanguage does not require POST inside the action and reads url and zip through the generic request input. A GET request can therefore reach the action without the trait checking a token. The action still requires core.tools , but that is the victim’s permission check; it does not prove that the privileged user intended the request.
Title Joomla Extension - balbooa.com - CSRF in language installation feature Gridbox < 2.20.4.0
Weaknesses CWE-352
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Balbooa.com Gridbox Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-10-08T14:11:17.016Z

Reserved: 2026-09-29T16:46:15.045Z

Link: CVE-2026-102784

cve-icon Vulnrichment

Updated: 2026-10-08T14:11:13.904Z

cve-icon NVD

Status : Received

Published: 2026-10-08T13:17:12.023

Modified: 2026-10-08T15:17:31.097

Link: CVE-2026-102784

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T15:45:11Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)