Executive brief
Gridbox is a popular drag-and-drop page builder used to design and manage Joomla websites. Multiple security flaws in the administrative interface allow attackers to perform unauthorized actions by tricking a logged-in administrator into clicking a malicious link or visiting a compromised site. This could lead to unauthorized changes to website content, configuration tampering, or other administrative actions without the site owner's consent.
Technical details
The Gridbox extension for Joomla (com_gridbox) fails to implement sufficient anti-CSRF tokens (nonce validation) across various endpoints in its administrative interface. An attacker can exploit this by crafting malicious web pages that, when visited by an authenticated administrator, trigger unintended state-changing requests to the Joomla backend. These vectors allow for various administrative actions to be performed on behalf of the victim. The vulnerabilities were identified during a comprehensive security audit by mySites.guru and are addressed in version 2.20.2.
Affected products
- balbooa.com Gridbox extension for Joomla 1.0.0-2.20.1
Timeline
- 2026-07-29: disclosed
- 2026-07-29: advisory
- 2026-07-29: patched: Fixed in version 2.20.2