Impact
An insecure form processing logic in Balbooa Forms allows attackers to execute arbitrary code by submitting a form that contains the signature field type. This flaw is a code injection vulnerability that does not require authentication, enabling an attacker to execute commands on the host server with the web application’s privileges.
Affected Systems
The vulnerability affects the Joomla extension Balbooa Forms component provided by balbooa.com. Any installation using a version earlier than 2.4.3 is susceptible.
Risk and Exploitability
The CVSS score of 10 marks the flaw as critical, and the EPSS score of less than 1% indicates a low but non-zero probability of exploitation. Because the attacker does not need prior authentication and the threat is listed in the common weaknes enumeration as CWE-94, an exploit could lead to complete compromise of the affected Joomla site. The vulnerability is not currently listed in the CISA KEV catalog, but its severity warrants immediate attention.
OpenCVE Enrichment