Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Gridbox 2.20.3.1 fixes unauthenticated SQL injection

Balbooa has released Gridbox 2.20.3.1 for Joomla to fix a high-severity, unauthenticated blind SQL injection in the extension’s public blog author filter.

Research published by mySites.guru says the flaw allows an attacker to send crafted input through the blog author parameter and extract database information through response timing. The issue is reachable without an account on the front end of a Gridbox blog.

All Gridbox versions below 2.20.3.1 are affected, including 2.20.3 and 2.20.2.3. The vulnerability is classified as SQL injection and has been assessed by mySites.guru as High severity. No CVE identifier or published CVSS score has been assigned. The report says there is no evidence that this specific issue was exploited in the wild before the fix.

  • Update every Joomla site running Gridbox to 2.20.3.1.
  • Confirm the installed version under Joomla’s Extensions management screen.
  • If an immediate update is impossible, unpublish front-end Gridbox blog views exposing the author filter until the update can be applied.
  • Review administrator accounts, users and active sessions after updating.

Originally reported by mySites.guru.