Unauthorized Deletion Vulnerability in Balbooa Forms by Joomla Extension
CVE-2026-101112
6.9MEDIUM
What is CVE-2026-101112?
A security vulnerability in the Balbooa Forms Joomla extension allows unauthorized users to delete attachments through the public removeTmpAttachment action. The action accepts an integer attachment ID and deletes the corresponding database entry and file. While session tokens are used to mitigate cross-site request forgery (CSRF) attacks, they do not ensure that the attachment belongs to the session that uploaded it. This flaw means that any guest can exploit this endpoint, potentially deleting attachments without proper authorization checks.
Affected Version(s)
Balbooa Forms extension for Joomla 1.0.0-2.4.3.3
