Impact
The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full remote code execution. By uploading malicious files, an attacker can execute code on the server, gaining complete control over the Joomla installation. This flaw aligns with CWE-434 and is considered a critical vulnerability.
Affected Systems
All instances of the Balbooa Forms extension for Joomla with a version earlier than 2.4.1 are affected. The vulnerability applies to any website that has deployed these legacy versions of the extension and has not applied the latest update from balbooa.com.
Risk and Exploitability
The CVSS score of 10 indicates maximum severity. The EPSS score of 76% indicates a high probability of exploitation; however, the ability to upload arbitrary files without authentication means attackers can exploit it if they have sufficient motivation, especially against exposed web servers. The vulnerability is listed in CISA’s KEV catalog, highlighting that it is actively exploited. Attackers can exploit the flaw without needing to authenticate, making it easily accessible to the general threat landscape.
OpenCVE Enrichment