Impact
The Balbooa Forms extension for Joomla is vulnerable to an unauthenticated arbitrary file upload flaw that permits attackers to upload executable files. Successfully uploaded executables can be executed, granting full control over the affected Joomla installation. This flaw is classified as a critical Remote Code Execution weakness, represented by CWE-434.
Affected Systems
All instances of the Balbooa Forms extension for Joomla with a version earlier than 2.4.1 are affected. The vulnerability applies to any website that has deployed these legacy versions of the extension and has not applied the latest update from balbooa.com.
Risk and Exploitability
The CVSS score of 10 indicates maximum severity. The EPSS score of 76% indicates a high probability of exploitation; however, the ability to upload arbitrary files without authentication means attackers can still exploit it if they have sufficient motivation, especially against exposed web servers. The vulnerability is listed in CISA’s KEV catalog, highlighting that it is actively exploited. Attackers can exploit the flaw without needing to authenticate, making it easily accessible to the general threat landscape.
OpenCVE Enrichment