PT-2026-102704 · Joomla · Balbooa Forms

·

CVE-2026-101112

·

Published

2026-09-29

·

Updated

2026-10-01

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Balbooa Forms versions prior to 2.4.3.4
Description An issue exists where the public removeTmpAttachment action allows the deletion of database rows and files by accepting an integer attachment ID. While the controller verifies a Joomla session token to prevent Cross-Site Request Forgery (CSRF)—a type of attack that forces an authenticated user to execute unwanted actions—the model fails to authorize the target object. It does not bind the attachment ID to the session that uploaded the file, the current user, the form, the upload field, or the temporary state, allowing any guest with a valid session token to delete attachments.
Recommendations Update to version 2.4.3.4 or later.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101112

Affected Products

Balbooa Forms