SQL Injection in Balbooa Forms Plugin for Joomla
CVE-2025-49485

8.6HIGH

Key Information:

Vendor
CVE Published:
18 July 2025

What is CVE-2025-49485?

The Balbooa Forms plugin for Joomla is susceptible to a SQL injection vulnerability that allows users with elevated privileges to execute arbitrary SQL commands through the manipulation of the 'id' parameter. This security flaw poses a significant risk as it could be exploited to compromise the integrity of the database and extract sensitive information, making it essential for website administrators to apply necessary patches and monitor their installations.

Affected Version(s)

Balbooa Forms component for Joomla 1.0.0-2.3.1.1

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kamil Szczurowski
Robert Kruczek
.
CVE-2025-49485 : SQL Injection in Balbooa Forms Plugin for Joomla