Executive brief
Gridbox, a popular drag-and-drop website builder for the Joomla content management system, contains a security flaw in its photo viewer component. This vulnerability allows an unauthorized person to view sensitive files on the web server without needing a username or password. An attacker could use this to access configuration files or other private data, potentially leading to a full site compromise or data breach.
Technical details
A path traversal vulnerability (CWE-22) exists in the photo viewer component of the Balbooa Gridbox extension for Joomla. The flaw allows an unauthenticated remote attacker to bypass directory restrictions and read arbitrary files on the server by providing manipulated file paths to the affected endpoint. This vulnerability is part of a larger set of 23 critical flaws identified in the extension. The issue is resolved in Gridbox version 2.20.2. Exploitation in the wild has been reported for vulnerabilities within this suite of findings.
Affected products
- balbooa.com Gridbox extension for Joomla 1.0.0-2.20.1
Timeline
- 2026-07-20: patched: Initial partial fixes in version 2.20.1
- 2026-07-29: advisory: Full disclosure of 23 vulnerabilities including this file read flaw
- 2026-07-29: patched: Final fixes released in version 2.20.2