Impact
Balbooa Forms processes JSON arrays for file uploads, checking only that IDs are numeric. It trusts client‑supplied filenames and display names without validation. This omission permits an attacker to submit crafted file metadata that can claim files created by other users, manipulate file paths, or cause path traversal. The result is potential unauthorized access to or replacement of files on the server, leading to data tampering or leakage.
Affected Systems
Balbooa Forms extension for Joomla from balbooa.com, versions earlier than 2.4.3.4. This includes all installations that have not yet applied the 2.4.3.4 release, which contains the fix.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate risk. EPSS data is not available, so the likelihood of exploitation cannot be quantified. It is not listed in KEV. Based on the description, it is inferred that the likely attack vector involves submitting crafted form data to the Balbooa Forms extension, as the vulnerability is exercised during file upload processing. Attacks can be launched remotely by sending HTTP requests to the form, potentially from authenticated or unauthenticated sessions depending on the site's configuration. The presence of path traversal and metadata manipulation weaknesses increases the potential impact on confidentiality and integrity of user data and files.
OpenCVE Enrichment