Impact
The vulnerability allows an attacker to modify the charge amount, line items, quantities, and shipping parameters sent to two payment endpoints, bypassing any server‑side calculation of the total. Because the endpoints lack authentication or CSRF protection, a remote actor can submit arbitrary values and force a purchase of any priced item for as little as one cent, or forge multiple line items and inflate costs. This can lead to unauthorized financial transactions, revenue loss, and potential reputational damage. The weakness is a classic authorization and input validation flaw, identified as CWE‑472 and CWE‑602.
Affected Systems
The affected component is the Balbooa Forms extension for Joomla, released by balbooa.com, for all versions earlier than 2.4.3.2. No further vendor or product versions are specified in the advisory.
Risk and Exploitability
The CVSS score of 7.7 classifies the flaw as high severity. The EPSS score of <1% indicates a very low but nonzero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote web request to the stripeCharges or payAuthorize endpoints, and the attack requires no authentication.
OpenCVE Enrichment