CVE-2026-102784
Received Received - Intake

CSRF in Gridbox Joomla Extension before 2.20.4.0

Vulnerability report for CVE-2026-102784, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Joomla! Project

Description

Joomla Extension - balbooa.com - CSRF in language installation feature Gridbox < 2.20.4.0 - PagesController uses a trait that validates the Joomla session token only when the HTTP method is POST. addLanguage does not require POST inside the action and reads url and zip through the generic request input. A GET request can therefore reach the action without the trait checking a token. The action still requires core.tools , but that is the victim’s permission check; it does not prove that the privileged user intended the request.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
balbooa.com Gridbox extension for Joomla 1.0.0-2.20.3.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Cross-Site Request Forgery (CSRF) issue in the Gridbox Joomla extension versions before 2.20.4.0. It allows an attacker to trick a user into making a malicious request via a GET request, bypassing session token validation. The PagesController trait only checks the token for POST requests, but the addLanguage action accepts GET requests without proper validation.

Detection Guidance

This vulnerability involves a CSRF flaw in the Gridbox Joomla extension where a GET request can trigger language installation without proper session validation. To detect it, inspect Joomla server logs for unusual GET requests to /administrator/components/com_gridbox/controllers/pages.php?task=addLanguage. Check if any unauthorized language installations occurred without a POST request containing a valid Joomla session token.

Impact Analysis

An attacker could exploit this to install unauthorized languages on your Joomla site without your consent. This could lead to defacement, unauthorized content changes, or further compromise of your website if the attacker gains control over language files or settings.

Compliance Impact

This vulnerability allows unauthorized language installation via a CSRF attack due to missing session token validation in GET requests. While it does not directly impact GDPR or HIPAA compliance, it could lead to unauthorized modifications of website content or configurations, potentially violating data integrity or access control requirements under these regulations if exploited.

Mitigation Strategies

Update the Gridbox extension for Joomla to version 2.20.4.0 or later to address the CSRF vulnerability in the language installation feature.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-102784. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart