Joomla Extension - balbooa.com - CSRF in language installation feature Gridbox < 2.20.4.0 - PagesController uses a trait that validates the Joomla session token only when the HTTP method is POST. addLanguage does not require POST inside the action and reads url and zip through the generic request input. A GET request can therefore reach the action without the trait checking a token. The action still requires core.tools , but that is the victim’s permission check; it does not prove that the privileged user intended the request.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

Thu, 08 Oct 2026 12:45:00 +0000

Type Values Removed Values Added
Description Joomla Extension - balbooa.com - CSRF in language installation feature Gridbox < 2.20.4.0 - PagesController uses a trait that validates the Joomla session token only when the HTTP method is POST. addLanguage does not require POST inside the action and reads url and zip through the generic request input. A GET request can therefore reach the action without the trait checking a token. The action still requires core.tools , but that is the victim’s permission check; it does not prove that the privileged user intended the request.
Title Joomla Extension - balbooa.com - CSRF in language installation feature Gridbox < 2.20.4.0
Weaknesses CWE-352
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-10-08T14:11:17.016Z

Reserved: 2026-09-29T16:46:15.045Z

Link: CVE-2026-102784

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T13:17:12.023

Modified: 2026-10-08T13:17:12.023

Link: CVE-2026-102784

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses