Impact
The Gridbox extension for Joomla contains a flaw in its socialLogin method that enables an attacker to authenticate as any user on the site, bypassing the normal login process and granting full access to that account. This improper authorization vulnerability, identified as an authorization issue (CWE-284), allows an attacker to assume the privileges of the compromised user, exposing the confidentiality, integrity, and availability of the affected accounts and site operations.
Affected Systems
The balbooa.com Gridbox extension for Joomla is vulnerable when its version is lower than 2.20.2. All installed instances below that version boundary are susceptible; no other version ranges are specified, so any pre‑2.20.2 release should be treated as affected.
Risk and Exploitability
The CVSS score of 10 highlights the critical nature of this flaw, while the EPSS score of less than 1% indicates rare exploitation at present. The socialLogin method is exposed via the public login interface; the likely attack vector is remote over the network. Although the flaw is not listed in the CISA KEV catalog, the high severity and potential for remote abuse warrant immediate attention.
OpenCVE Enrichment