Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.balbooa.com/gridbox |
|
Thu, 08 Oct 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 08 Oct 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Balbooa.com
Balbooa.com gridbox Extension For Joomla |
|
| Vendors & Products |
Balbooa.com
Balbooa.com gridbox Extension For Joomla |
Thu, 08 Oct 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joomla Extension - balbooa.com - CSRF in language installation feature Gridbox < 2.20.4.0 - PagesController uses a trait that validates the Joomla session token only when the HTTP method is POST. addLanguage does not require POST inside the action and reads url and zip through the generic request input. A GET request can therefore reach the action without the trait checking a token. The action still requires core.tools , but that is the victim’s permission check; it does not prove that the privileged user intended the request. | |
| Title | Joomla Extension - balbooa.com - CSRF in language installation feature Gridbox < 2.20.4.0 | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Joomla
Published:
Updated: 2026-10-08T14:11:17.016Z
Reserved: 2026-09-29T16:46:15.045Z
Link: CVE-2026-102784
Updated: 2026-10-08T14:11:13.904Z
Status : Awaiting Analysis
Published: 2026-10-08T13:17:12.023
Modified: 2026-10-08T21:07:57.460
Link: CVE-2026-102784
No data.
OpenCVE Enrichment
Updated: 2026-10-08T15:45:11Z
-
CWE-352
Cross-Site Request Forgery (CSRF)