Impact
The Gridbox extension for Joomla contains an improper access control flaw (CWE‑285). The vulnerability allows an attacker to manipulate the payment workflow, enabling them to obtain services or proceed with purchases without paying the required amount. While it does not expose code execution or data exfiltration, the impact includes financial loss and potential fraudulent transactions, compromising the integrity of the vendor’s revenue stream.
Affected Systems
All Joomla sites running balbooa.com’s Gridbox extension version 2.20.2 or earlier are affected. The vulnerability applies to any installation managed through the extension’s payment routines.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of widespread exploitation currently, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires access to the Joomla site’s administrative interface or a crafted request that manipulates payment parameters; the attack vector is likely web‑based and limited to environments where the extension is enabled.
OpenCVE Enrichment