Impact
An unauthenticated user can trigger the generateNewApp method in the Gridbox extension for Joomla to perform recursive directory deletion. This flaw permits removal of arbitrary paths within the Joomla installation, leading to potential loss of site content, configuration files, and user data. The weakness combines malicious directory traversal (CWE‑22) with insufficient access control (CWE‑284).
Affected Systems
The vulnerability affects the balbooa.com Gridbox extension for Joomla, versions older than 2.20.2. Only installations that have not applied the recent patch are impacted.
Risk and Exploitability
The CVSS score of 9.2 classifies the issue as critical, and the EPSS score of less than 1% indicates a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires no authentication; an attacker can send an unauthenticated HTTP request to the vulnerable endpoint, triggering the recursive deletion. Successful exploitation would result in loss of files and service disruption.
OpenCVE Enrichment