PT-2026-102704 · Joomla · Balbooa Forms
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Balbooa Forms versions prior to 2.4.3.4
Description
An issue exists where the public
removeTmpAttachment action allows the deletion of database rows and files by accepting an integer attachment ID. While the controller verifies a Joomla session token to prevent Cross-Site Request Forgery (CSRF)—a type of attack that forces an authenticated user to execute unwanted actions—the model fails to authorize the target object. It does not bind the attachment ID to the session that uploaded the file, the current user, the form, the upload field, or the temporary state, allowing any guest with a valid session token to delete attachments.Recommendations
Update to version 2.4.3.4 or later.
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Balbooa Forms