CyberRota Analysis
AI-GeneratedThe Balbooa Forms extension for Joomla versions prior to 2.4.3.4 is vulnerable to unauthenticated remote code execution (RCE) due to improper handling of field shortcode injections in PHP code executed after form submissions. This vulnerability allows attackers to inject malicious PHP code through user-controlled form fields, potentially compromising the server. Organizations using this extension should prioritize immediate patching to mitigate the risk of exploitation.
Original NVD Description
Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa Forms supports administrator-defined PHP code which runs after a public form submission. The feature also supports form-field shortcodes inside that PHP. Before calling `eval()`, the component replaces each shortcode with the raw value submitted by the visitor, leading to an RCE vector. A public form must use the product's optional PHP-after-submission action and interpolate an attacker-controlled field shortcode inside a double-quoted PHP string to be vulnerable.
Related CVEs
Other vulnerabilities affecting the same vendor(s)