Impact
An unauthenticated attacker can inject SQL statements into Gridbox queries, as the extension does not properly sanitize input. The vulnerability is a classic SQL injection (CWE-89) that allows actors to read, modify, or delete data housed in the Joomla site's database, potentially leading to full data compromise or further exploitation if the database user has elevated privileges.
Affected Systems
The Gridbox extension for Joomla, distributed by balbooa.com, is affected for all releases older than 2.20.2. Sites that have not yet upgraded to 2.20.2 or newer versions remain vulnerable.
Risk and Exploitability
The CVSS score of 9.2 marks this flaw as severe and the fact that it is unauthenticated raises the urgency of mitigation. The EPSS score of less than 1% indicates a low current probability of exploitation, and the vulnerability is not listed in CISA KEV. Nonetheless, the potential impact on data confidentiality and integrity is high, and the attack vector is a web request to the Joomla presentation layer that does not require authentication.
OpenCVE Enrichment