Impact
The Joomla extension Gridbox is vulnerable to an authentication bypass, potentially leading to full admin access. This flaw allows an attacker to circumvent standard authentication mechanisms and gain unrestricted administrative privileges, as described in the updated vulnerability description. The issue is categorized as CWE‑288 and carries a CVSS score of 9.4, indicating a severe risk to confidentiality, integrity, and availability.
Affected Systems
All installations of the Balbooa.com Gridbox Joomla extension using version 1.5.x or older are affected. The flaw applies regardless of the Joomla core version, impacting every site that has not upgraded to the patched 1.6.0 release.
Risk and Exploitability
The high CVSS rating indicates a critical risk level, while the EPSS score of less than 1% suggests that exploitation is currently unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog, implying no widespread public exploits at this time. Attackers can exploit the flaw by manipulating authentication flows or logging in with arbitrary credentials to gain full admin control over the site. Given the severity and potential impact on site integrity and confidentiality, immediate remedial action is strongly recommended.
OpenCVE Enrichment