Impact
The Gridbox Joomla extension contains a flaw in its resetPassword method that permits an unauthenticated actor to reset any user account’s password except super administrators. No authentication or authorization is required before changing credentials, enabling an attacker to assume the identity of any site user and use the user’s permissions to access sensitive data or perform further malicious actions.
Affected Systems
The vulnerable product is the Gridbox extension for Joomla, released by balbooa.com. Versions prior to 2.20.2 contain the flaw; versions 2.20.2 and later address it.
Risk and Exploitability
The CVSS score of 10 indicates critical severity. The EPSS score of less than 1% suggests the vulnerability is not frequently exploited. It is not listed in the CISA KEV catalog. Attackers can easily exploit the flaw by calling the resetPassword endpoint with a valid or guessed user identifier, resetting the password, and then logging in as that user. No special conditions are required, making the risk high if the patch is not applied.
OpenCVE Enrichment