Impact
The vulnerability allows attackers to request the photo viewer route within the Gridbox Joomla extension and retrieve the contents of arbitrary files stored on the web server. This is a path traversal flaw (CWE-22) that can expose sensitive configuration files, user credentials, or other confidential data, potentially leading to information disclosure.
Affected Systems
Gridbox extension for Joomla from balbooa.com, versions prior to 2.20.2, is affected. Any installation of this extension that has not been upgraded to 2.20.2 or later is vulnerable.
Risk and Exploitability
The CVSS score of 9.2 highlights a severe confidentiality risk. The EPSS value of less than 1% indicates that current exploitation likelihood is minimal, and the issue is not listed in CISA’s KEV. The likely attack vector is sending web requests to the photo viewer endpoint without authentication, allowing an attacker to read arbitrary files from any network location.
OpenCVE Enrichment