Impact
The Gridbox extension for Joomla allows the registration method to accept arbitrary usergroup IDs, permitting an unauthenticated actor to create a new account with administrative permissions. This flaw enables a privilege escalation attack that can give the attacker full control over the Joomla site. The vulnerability is categorized as a CWE-284 deficiency in access control and is also listed by NVD as NVD-CWE-noinfo, indicating an associated unclassified weakness.
Affected Systems
The flaw affects the Gridbox extension from balbooa.com when its version is older than 2.20.2. Users running any release below this version are susceptible.
Risk and Exploitability
With a CVSS score of 10 the flaw is considered critical. The EPSS score of less than 1% indicates that, while exploitation is not yet widespread, the flaw is trivially reachable through the public registration endpoint and requires no special access; any user can submit a registration request with an elevated usergroup ID. The vulnerability is not currently listed in the CISA KEV catalog, but the potential for a complete takeover of the site makes it a high priority for remediation.
OpenCVE Enrichment