What the vulnerability does
01Description
Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.
CVSS base score
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red
What the vulnerability does
Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user on the target site.
Explanation of Vulnerability in Simple Terms
The Gridbox extension for Joomla contains an access control flaw that allows unauthenticated attackers to read, modify, or delete sensitive data and disrupt site operations. The vulnerability requires only network access and can be exploited without user interaction. All versions from 1.0.0 through 2.20.1 are affected.
What an attacker can do
Read, modify, or delete sensitive data; disrupt site availability without authentication.
Potential impact on your site
Attackers can access private content, alter site data, or take the site offline without logging in.
Conditions required to exploit
Network access only; no authentication or user interaction required.
Key dates
External resources
Related vulnerabilities