OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-102424

HIGH · CVSS 7.5 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The Balbooa Forms extension for Joomla versions prior to 2.4.3.4 is vulnerable to unauthenticated path traversal, allowing attackers to exfiltrate local files by manipulating the upload-field state during public form submissions. This flaw can lead to the exposure of sensitive files, such as configuration data, to unauthorized users via email attachments. Organizations using this extension should prioritize patching to mitigate the risk of data breaches and unauthorized access.

CVE
CVE-2026-102424
Severity
HIGH
CVSS
7.5
EPSS
0.37%

Original NVD Description

Joomla Extension - balbooa.com - Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4 - Balbooa Forms accepts upload-field state as Guest-controlled JSON during public form submission. For every object whose `id` merely looks numeric, the component trusts the supplied `filename`, concatenates it below the configured upload directory, and adds the result to an array of local attachment paths. It does not load the referenced attachment row, verify ownership/session/form/field, require that the ID exists, canonicalize the path, or enforce containment. If the form's normal “auto reply” and “attach uploaded files” options are enabled, the component sends those local paths as email attachments to the address submitted in an email field. A Guest can therefore submit a nonexistent numeric ID plus a traversal filename such as `../../../../configuration.php` and receive any file readable by the Joomla process.

Related CVEs

Other vulnerabilities affecting the same vendor(s)