What the vulnerability does
01Description
Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.
CVSS base score
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
What the vulnerability does
Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, potentially leading to full admin access.
Explanation of Vulnerability in Simple Terms
The Gridbox extension for Joomla contains an authentication bypass vulnerability affecting version 1.0.0-2.20.0.2. An attacker with high-level privileges can exploit this flaw to gain unauthorized access to sensitive functionality. The vulnerability requires network access but no user interaction. Site administrators should update to a patched version when available.
What an attacker can do
Bypass authentication controls to access restricted functionality within the Gridbox extension.
Potential impact on your site
Administrators with high privileges could exploit this to access unauthorized features; update when patched version is released.
Conditions required to exploit
Attacker must have high-level administrative privileges on the Joomla site.
Key dates
External resources
Related vulnerabilities