🔐 CVE Alert

CVE-2026-102424

UNKNOWN 0.0

Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4 - Balbooa Forms accepts upload-field state as Guest-controlled JSON during public form submission. For every object whose `id` merely looks numeric, the component trusts the supplied `filename`, concatenates it below the configured upload directory, and adds the result to an array of local attachment paths. It does not load the referenced attachment row, verify ownership/session/form/field, require that the ID exists, canonicalize the path, or enforce containment. If the form's normal “auto reply” and “attach uploaded files” options are enabled, the component sends those local paths as email attachments to the address submitted in an email field. A Guest can therefore submit a nonexistent numeric ID plus a traversal filename such as `../../../../configuration.php` and receive any file readable by the Joomla process.

CWE CWE-22
Vendor balbooa.com
Product balbooa forms extension for joomla
Published Sep 29, 2026
Stay Ahead of the Next One

Get instant alerts for balbooa.com balbooa forms extension for joomla

Be the first to know when new unknown vulnerabilities affecting balbooa.com balbooa forms extension for joomla are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

balbooa.com / Balbooa Forms extension for Joomla
1.0.0-2.4.3.3

References

NVD ↗ CVE.org ↗ EPSS Data ↗
balbooa.com: https://www.balbooa.com/

Credits

Łukasz Rybak