Description
Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4 - Balbooa Forms accepts upload-field state as Guest-controlled JSON during public form submission. For every object whose `id` merely looks numeric, the component trusts the supplied `filename`, concatenates it below the configured upload directory, and adds the result to an array of local attachment paths. It does not load the referenced attachment row, verify ownership/session/form/field, require that the ID exists, canonicalize the path, or enforce containment. If the form's normal “auto reply” and “attach uploaded files” options are enabled, the component sends those local paths as email attachments to the address submitted in an email field. A Guest can therefore submit a nonexistent numeric ID plus a traversal filename such as `../../../../configuration.php` and receive any file readable by the Joomla process.
Published: 2026-09-29
Score: 8.9 High
EPSS: n/a
KEV: No
Impact: Local File Disclosure via Email Attachment
Action: Patch ASAP
AI Analysis

Impact

Balbooa Forms processes upload-field state as untrusted JSON in public form submissions. For any numeric ID, the extension trusts the supplied filename and concatenates it under the configured upload directory, generating a local attachment path without validating ownership, canonicalizing the path, or ensuring the ID exists. When auto‑reply and attachment options are enabled, the system emails these local paths to the address supplied in the form, exposing any file readable by the Joomla process. The vulnerability is a path traversal flaw (CWE‑22) that allows an unauthenticated attacker to request any server file as an email attachment, compromising confidentiality.

Affected Systems

The Balbooa Forms extension for Joomla versions older than 2.4.3.4 is affected. The flaw exists in all earlier releases of the extension and can be exploited by default installations that expose the public form submission interface.

Risk and Exploitability

With a CVSS score of 8.9 the vulnerability scores high severity. EPSS is not reported, so the exploitation probability is currently unknown but the lack of authentication requirement and direct file disclosure make it attractive to attackers. The flaw is not listed in CISA KEV, but its high impact and unauthenticated nature suggest it could be abused in targeted or opportunistic attacks through the public form. Attackers can craft a malicious JSON payload with a numeric ID and a traversal filename such as ../../../../configuration.php, submit the form, and receive the target file as an email attachment to an address of their choosing.

Generated by OpenCVE AI on September 30, 2026 at 00:15 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Balbooa Forms to version 2.4.3.4 or later, which removes the unsafe handling of upload-field IDs.
  • Until a patch is available, disable the auto‑reply and attach uploaded files options in the form settings, or remove the form from publicly accessible URLs.
  • Implement server‑side validation to ensure upload-field IDs exist, canonicalize file paths, and enforce that generated attachment paths remain within the designated upload directory.

Generated by OpenCVE AI on September 30, 2026 at 00:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.balbooa.com/ cve-icon cve-icon
History

Tue, 29 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Description Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4 - Balbooa Forms accepts upload-field state as Guest-controlled JSON during public form submission. For every object whose `id` merely looks numeric, the component trusts the supplied `filename`, concatenates it below the configured upload directory, and adds the result to an array of local attachment paths. It does not load the referenced attachment row, verify ownership/session/form/field, require that the ID exists, canonicalize the path, or enforce containment. If the form's normal “auto reply” and “attach uploaded files” options are enabled, the component sends those local paths as email attachments to the address submitted in an email field. A Guest can therefore submit a nonexistent numeric ID plus a traversal filename such as `../../../../configuration.php` and receive any file readable by the Joomla process.
Title Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 8.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-09-29T17:07:25.975Z

Reserved: 2026-09-29T04:38:08.434Z

Link: CVE-2026-102424

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T17:17:06.070

Modified: 2026-09-29T21:39:02.570

Link: CVE-2026-102424

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T00:30:17Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')