Executive brief
A vulnerability in the Gridbox page builder for Joomla allows unauthorized users to bypass payment processes. Gridbox is a popular tool used to build websites, online stores, and booking systems. An attacker could exploit this flaw to complete transactions or access premium features without making a valid payment, leading to direct financial loss for site owners.
Technical details
A payment bypass vulnerability exists in the Balbooa Gridbox extension for Joomla (com_gridbox) in versions prior to 2.20.2. The flaw resides in the handling of payment processing logic, where insufficient validation allows a remote, unauthenticated attacker to bypass the payment step of a transaction. This is part of a larger set of 23 vulnerabilities discovered in the component, which stem from a systemic failure to validate request parameters. An attacker can exploit this to obtain goods or services without authorization. The issue is resolved in version 2.20.2.
Affected products
- balbooa.com Gridbox extension for Joomla 1.0.0-2.20.1
Timeline
- 2026-07-20: patched: Initial partial fixes released in version 2.20.1
- 2026-07-29: advisory: Full disclosure of 23 vulnerabilities including payment bypass
- 2026-07-29: patched: Final fix released in version 2.20.2