Unauthorized Deletion Vulnerability in Balbooa Forms by Joomla Extension
CVE-2026-101112

6.9MEDIUM

Key Information:

Vendor
CVE Published:
29 September 2026

What is CVE-2026-101112?

A security vulnerability in the Balbooa Forms Joomla extension allows unauthorized users to delete attachments through the public removeTmpAttachment action. The action accepts an integer attachment ID and deletes the corresponding database entry and file. While session tokens are used to mitigate cross-site request forgery (CSRF) attacks, they do not ensure that the attachment belongs to the session that uploaded it. This flaw means that any guest can exploit this endpoint, potentially deleting attachments without proper authorization checks.

Affected Version(s)

Balbooa Forms extension for Joomla 1.0.0-2.4.3.3

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sergiy Tryzhychynskyi
.