Impact
Balbooa Forms extension for Joomla allows administrators to define custom PHP code that runs after a form submission. The extension replaces each form-field shortcode with the raw data submitted by a visitor before executing eval(). An attacker can inject a shortcode that expands into malicious PHP inside a double‑quoted string, enabling unauthenticated remote code execution. This fault is a classic code injection vulnerability (CWE‑94).
Affected Systems
The balbooa.com Balbooa Forms extension for Joomla, any version earlier than 2.4.3.4, is affected.
Risk and Exploitability
The CVSS score of 9.5 reflects this high‑severity flaw. No EPSS value is available, so the exact exploitation probability cannot be quantified, and the vulnerability is not listed in the CISA KEV catalog. An attacker only needs a publicly accessible form that uses the PHP‑after‑submission action and contains a vulnerable shortcode; because the injected code runs under the web server’s privileges, successful exploitation could lead to complete compromise of the web application.
OpenCVE Enrichment