PT-2026-65785 · Balbooa.Com+1 · Gridbox Extension For Joomla+1
CVSS v4.0
10
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red |
Name of the Vulnerable Software and Affected Versions
Gridbox versions prior to 2.20.2
Description
A privilege escalation issue exists in the registration method of the Gridbox extension for Joomla. This flaw allows unauthenticated actors to register new accounts with administrative permissions by providing specific usergroup IDs.
Recommendations
Update Gridbox to version 2.20.2 or later.
Fix
LPE
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gridbox Extension For Joomla
Gridbox