---
id: CVE-2026-102784
title: >-
  Joomla Extension - balbooa.com - CSRF in language installation feature Gridbox
  < 2.20.4.0 - PagesController uses a trait that validates the Joomla session
  token only when the HTTP method is POST
summary: >-
  Joomla Extension - balbooa.com - CSRF in language installation feature Gridbox
  < 2.20.4.0 - PagesController uses a trait that validates the Joomla session
  token only when the HTTP method is POST. addLanguage does not require POST
  inside …
severity: high
cvss: 8.7
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-352
vendor: balbooa.com
product: com_gridbox
affected:
  - com_gridbox 1.0.0-2.20.3.1
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T15:17:31.097'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-102784'
references:
  - url: 'https://www.balbooa.com/gridbox'
    label: security@joomla.org
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-08T14:11:09.919123Z'
cvssSource: cna
ingestedAt: '2026-10-08T12:39:48.762Z'
---

## Overview

Joomla Extension - balbooa.com - CSRF in language installation feature Gridbox < 2.20.4.0 - PagesController uses a trait that validates the Joomla session token only when the HTTP method is POST. addLanguage does not require POST inside the action and reads url and zip through the generic request input. A GET request can therefore reach the action without the trait checking a token. The action still requires core.tools , but that is the victim’s permission check; it does not prove that the privileged user intended the request.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
