Impact
An attacker can exploit a cross‑site request forgery (CSRF) flaw in the Gridbox extension for Joomla. The addLanguage action accepts GET requests and reads a language pack URL and ZIP file from the query string without enforcing the Joomla session token, because the security trait that validates the token is applied only to POST methods. This allows an attacker to trigger the installation of an arbitrary language pack. Based on the description, it is inferred that an attacker could introduce malicious code into the site through a malicious language pack, potentially leading to unintended code execution or site compromise, though the CVE text does not explicitly confirm this outcome.
Affected Systems
All installations of balbooa.com’s Gridbox extension for Joomla with versions earlier than 2.20.4.0 are affected. The issue occurs in the PagesController trait used by the addLanguage function and applies to any deployment using those pre‑2.20.4.0 releases.
Risk and Exploitability
The CVSS base score of 8.7 indicates high severity. The attack can be performed over the network by sending a crafted GET request to the addLanguage endpoint. No EPSS score is available, so the current exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog, indicating no publicly known exploits yet. However, sites with administrators granted the core.tools permission are at high risk, because the permission check is the only remaining safeguard and does not confirm the user’s intent.
OpenCVE Enrichment