CVE-2026-102784

In der Erweiterung von Joomla von balbooa.

Description

Joomla Extension - balbooa.com - CSRF in language installation feature Gridbox < 2.20.4.0 - PagesController uses a trait that validates the Joomla session token only when the HTTP method is POST. addLanguage does not require POST inside the action and reads url and zip through the generic request input. A GET request can therefore reach the action without the trait checking a token. The action still requires core.tools , but that is the victim’s permission check; it does not prove that the privileged user intended the request.

Metrics

8.7
Source: cna-v4
5.9 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
Show all metrics
Severity
high
no public PoC known
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-10-08 12:32 UTC
CWE-352

Weakness classes (CWE)

  • CWE-352Compound

    Cross-Site Request Forgery (CSRF)

    The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-10-08 15:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-102784","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technical…
  2. New CVE Received2026-10-08 13:17 UTC· security@joomla.org
    • Description: Joomla Extension - balbooa.com - CSRF in language installation feature Gridbox < 2.20.4.0 - PagesController uses a trait that validates the Joomla session token only when the HTTP method is POST. addLanguage does not require POST inside the action and reads url and zip through the generic request input. A GET request can therefore reach the action without the trait checking a token. The action still requires core.tools , but that is the victim’s permission check; it does not prove that the privileged user intended the request.
    • CVSS V4.0: AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    • CWE: CWE-352
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/102xxx/CVE-2026-102784.json">CVE-2026-102784</a>