Impact
Balbooa Forms processes upload-field state as untrusted JSON in public form submissions. For any numeric ID, the extension trusts the supplied filename and concatenates it under the configured upload directory, generating a local attachment path without validating ownership, canonicalizing the path, or ensuring the ID exists. When auto‑reply and attachment options are enabled, the system emails these local paths to the address supplied in the form, exposing any file readable by the Joomla process. The vulnerability is a path traversal flaw (CWE‑22) that allows an unauthenticated attacker to request any server file as an email attachment, compromising confidentiality.
Affected Systems
The Balbooa Forms extension for Joomla versions older than 2.4.3.4 is affected. The flaw exists in all earlier releases of the extension and can be exploited by default installations that expose the public form submission interface.
Risk and Exploitability
With a CVSS score of 8.9 the vulnerability scores high severity. EPSS is not reported, so the exploitation probability is currently unknown but the lack of authentication requirement and direct file disclosure make it attractive to attackers. The flaw is not listed in CISA KEV, but its high impact and unauthenticated nature suggest it could be abused in targeted or opportunistic attacks through the public form. Attackers can craft a malicious JSON payload with a numeric ID and a traversal filename such as ../../../../configuration.php, submit the form, and receive the target file as an email attachment to an address of their choosing.
OpenCVE Enrichment