CVE-2026-102784highCWE-352

CVE-2026-102784: fallo de gravedad alta en balbooa.com Gridbox extension for Joomla

Joomla Extension - balbooa.com - CSRF in language installation feature Gridbox < 2.20.4.0

Publicada el

18Vexday Risk Score

Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.

ssvc Trackcvss 8.7
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
Joomla Extension - balbooa.com - CSRF in language installation feature Gridbox < 2.20.4.0 - PagesController uses a trait that validates the Joomla session token only when the HTTP method is POST. addLanguage does not require POST inside the action and reads url and zip through the generic request input. A GET request can therefore reach the action without the trait checking a token. The action still requires core.tools , but that is the victim’s permission check; it does not prove that the privileged user intended the request.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N