PT-2026-102706 · WordPress · Balbooa Forms
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Balbooa Forms versions prior to 2.4.3.4
Description
An unauthenticated stored Cross-Site Scripting (XSS) issue exists in the public form upload endpoint. While the endpoint validates file extensions and MIME types, it stores the original multipart filename provided by the user verbatim in the
# baforms submissions attachments.name field. A subsequent anonymous form submission can associate this temporary attachment with a new submission. When an administrator views the submission, the component's JavaScript retrieves the stored attachment record and concatenates the file.name variable directly into an HTML string, which is then assigned to innerHTML. XSS is a technique where malicious scripts are injected into trusted websites.Recommendations
Update Balbooa Forms to version 2.4.3.4 or later.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Balbooa Forms