Description
Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4 - The final form submission processes JSON arrays per upload field, checking only that IDs are numeric. Client-supplied filenames and display names are trusted directly, introducing potential cross-session claiming, metadata tampering, and path traversal risks (e.g., via getFilePath())
Published: 2026-09-29
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Cross-session file metadata tampering and potential path traversal leading to unauthorized file access
Action: Immediate Patch
AI Analysis

Impact

Balbooa Forms processes JSON arrays for file uploads, checking only that IDs are numeric. It trusts client‑supplied filenames and display names without validation. This omission permits an attacker to submit crafted file metadata that can claim files created by other users, manipulate file paths, or cause path traversal. The result is potential unauthorized access to or replacement of files on the server, leading to data tampering or leakage.

Affected Systems

Balbooa Forms extension for Joomla from balbooa.com, versions earlier than 2.4.3.4. This includes all installations that have not yet applied the 2.4.3.4 release, which contains the fix.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate risk. EPSS data is not available, so the likelihood of exploitation cannot be quantified. It is not listed in KEV. Based on the description, it is inferred that the likely attack vector involves submitting crafted form data to the Balbooa Forms extension, as the vulnerability is exercised during file upload processing. Attacks can be launched remotely by sending HTTP requests to the form, potentially from authenticated or unauthenticated sessions depending on the site's configuration. The presence of path traversal and metadata manipulation weaknesses increases the potential impact on confidentiality and integrity of user data and files.

Generated by OpenCVE AI on September 30, 2026 at 00:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Balbooa Forms to version 2.4.3.4 or later.
  • If an upgrade is not immediately possible, restrict form access to trusted users or disable file uploads entirely.
  • Implement server‑side validation to reject relative paths and enforce strict file path checks for uploaded files.

Generated by OpenCVE AI on September 30, 2026 at 00:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.balbooa.com/ cve-icon cve-icon
History

Tue, 29 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Description Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4 - The final form submission processes JSON arrays per upload field, checking only that IDs are numeric. Client-supplied filenames and display names are trusted directly, introducing potential cross-session claiming, metadata tampering, and path traversal risks (e.g., via getFilePath())
Title Joomla Extension - balbooa.com - File meta data tampering in Balbooa Forms < 2.4.3.4
Weaknesses CWE-22
CWE-73
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-09-29T17:02:38.500Z

Reserved: 2026-09-28T07:02:41.617Z

Link: CVE-2026-101126

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T17:17:05.050

Modified: 2026-09-29T21:39:02.570

Link: CVE-2026-101126

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T00:45:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-73

    External Control of File Name or Path