Horizon Alert
Summary of the vulnerability and why it matters
This advisory concerns a critical vulnerability in a Joomla extension that allows unauthenticated users to reset any user's password, except for super administrators. This could permit unauthorized access and actions on behalf of other users.
- Anyone can reset user passwords.
- It allows unauthorized account takeover.
- Confirm relevance and exposure to your systems.
Attack Path
How an attacker could exploit the issue
An attacker can remotely reset any user's password by interacting with the `resetPassword` method, enabling them to log in as the targeted user, except for super administrators.
- Unauthenticated access required.
- Vulnerable `resetPassword` method.
- Takeover of non-admin accounts.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an unauthenticated actor to reset any user's password, except for super administrators. When exploited, this could enable an attacker to log in as a regular user and perform actions on their behalf.
- User account access.
- Unauthenticated password reset.
- Unauthorized user actions.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Joomla extension owner and platform teams are likely responsible for addressing this critical vulnerability. The first practical step is to identify all Gridbox installations, confirm their exposure and business criticality, and then prioritize remediation based on risk, coordinating with the vendor as needed.
- Application owners must manage the issue.
- Verify Gridbox reachability and asset criticality.
- Plan vendor-coordinated remediation.