Description
Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4 - The public form upload endpoint validates the uploaded file's extension and detected MIME type, but stores the attacker-supplied original multipart filename verbatim in `#__baforms_submissions_attachments.name`. A later anonymous form submission associates that temporary attachment with the newly created submission. When an administrator opens the submission, the component's JavaScript retrieves the stored attachment record and concatenates `file.name` directly into an HTML string. The complete string is assigned to `innerHTML`.
Published: 2026-09-29
Score: 8.6 High
EPSS: n/a
KEV: No
Impact: Cross‑site scripting affecting administrator interface
Action: Apply patch
AI Analysis

Impact

The vulnerability serves as a stored cross‑site scripting flaw. A malicious user can upload a file whose original filename contains injected JavaScript. Because the filename is stored verbatim and later concatenated into the innerHTML of a submission view page, the malicious script runs in the browser context of any administrator opening that submission, enabling theft of session cookies and credential compromise.

Affected Systems

All sites running the Balbooa Forms extension for Joomla with a version earlier than 2.4.3.4 are affected. The issue arises wherever the public upload endpoint is exposed, regardless of Joomla version.

Risk and Exploitability

The CVSS score of 8.6 classifies this as high severity. An unauthenticated attacker can exploit the flaw by simply submitting a crafted file through a public form. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. However, the lack of authentication requirement and the ability to affect admin users make the risk significant.

Generated by OpenCVE AI on September 30, 2026 at 00:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Balbooa Forms extension to version 2.4.3.4 or newer, which contains the XSS fix.
  • Implement file‑name sanitization or validation to prevent injection if upgrading is delayed, ensuring that filenames are stripped of scriptable characters before storage.
  • Audit existing submissions and remove any stored filenames that may contain malicious content, then reset the affected administrator accounts.

Generated by OpenCVE AI on September 30, 2026 at 00:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.balbooa.com/ cve-icon cve-icon
History

Tue, 29 Sep 2026 17:00:00 +0000

Type Values Removed Values Added
Description Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4 - The public form upload endpoint validates the uploaded file's extension and detected MIME type, but stores the attacker-supplied original multipart filename verbatim in `#__baforms_submissions_attachments.name`. A later anonymous form submission associates that temporary attachment with the newly created submission. When an administrator opens the submission, the component's JavaScript retrieves the stored attachment record and concatenates `file.name` directly into an HTML string. The complete string is assigned to `innerHTML`.
Title Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-09-29T16:57:36.625Z

Reserved: 2026-09-28T07:02:41.617Z

Link: CVE-2026-101127

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T17:17:05.187

Modified: 2026-09-29T21:39:02.570

Link: CVE-2026-101127

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T00:30:17Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')