CyberRota Analysis
AI-GeneratedThe Gridbox extension for Joomla versions prior to 2.20.2 is vulnerable to an unauthenticated arbitrary password reset, enabling attackers to reset passwords for any user account, except for super admins. This flaw poses a significant risk as it allows unauthorized access to user accounts, potentially leading to data breaches or account takeovers. Joomla site administrators using the affected extension should prioritize applying the update to mitigate this security risk.
Original NVD Description
Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any user password, allowing to login and act as these users - excluding super admins.
Related CVEs
Other vulnerabilities affecting the same vendor(s)