Impact
The vulnerability serves as a stored cross‑site scripting flaw. A malicious user can upload a file whose original filename contains injected JavaScript. Because the filename is stored verbatim and later concatenated into the innerHTML of a submission view page, the malicious script runs in the browser context of any administrator opening that submission, enabling theft of session cookies and credential compromise.
Affected Systems
All sites running the Balbooa Forms extension for Joomla with a version earlier than 2.4.3.4 are affected. The issue arises wherever the public upload endpoint is exposed, regardless of Joomla version.
Risk and Exploitability
The CVSS score of 8.6 classifies this as high severity. An unauthenticated attacker can exploit the flaw by simply submitting a crafted file through a public form. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. However, the lack of authentication requirement and the ability to affect admin users make the risk significant.
OpenCVE Enrichment