Impact
The Gridbox extension for Joomla is vulnerable to unauthenticated file system disclosure all versions prior to 2.20.2. An attacker can request arbitrary files from the server without needing valid credentials, revealing potentially sensitive or confidential data. The weakness aligns with CWE‑200, which denotes unauthorized disclosure of information. No additional exploitation paths that could compromise system integrity or availability are indicated in the description.
Affected Systems
The vulnerability affects the balbooa.com Gridbox extension for Joomla. All releases below version 2.20.2 are at risk. The affected platform is Joomla-based websites that have installed Gridbox extensions older than the listed version.
Risk and Exploitability
The CVSS score of 5.3 classifies this vulnerability as moderate. The EPSS score of less than 1% suggests a low probability of exploitation under normal conditions, and the vulnerability is not listed in the CISA KEV catalog. However, because the exploit requires no authentication, the potential impact could be significant if sensitive files (e.g., configuration files, developer keys, or backups) are exposed. The attack vector is inferred to be a remote attacker making HTTP requests to the Joomla site hosting Gridbox, as the description states the flaw is unauthenticated.
OpenCVE Enrichment