CVE-2025-49485: Extension - balbooa.com - SQL injection in Balbooa Forms component version 1.0.0 - 2.3.1.1 for Joomla
Published Jul 18, 2025
·Updated
A SQL injection vulnerability in the Balbooa Forms plugin 1.0.0-2.3.1.1 for Joomla allows privileged users to execute arbitrary SQL commands via the 'id' parameter.
Affected Software
1 affected component
Balbooa Forms>=1.0.0<=2.3.1.1
Event History
Jul 18, 2025
CVE Published
via MITRE·09:51 AM
Data Sourced
via MITRE·09:51 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-49485?
CVE-2025-49485 has been classified as a critical SQL injection vulnerability.
2
How do I fix CVE-2025-49485?
To fix CVE-2025-49485, update the Balbooa Forms plugin to the latest version that resolves this vulnerability.
3
Who is affected by CVE-2025-49485?
Users of the Balbooa Forms plugin versions 1.0.0 to 2.3.1.1 for Joomla are affected by CVE-2025-49485.
4
What kind of attack does CVE-2025-49485 allow?
CVE-2025-49485 allows privileged users to execute arbitrary SQL commands through the 'id' parameter.
5
Is there a workaround for CVE-2025-49485?
A temporary workaround for CVE-2025-49485 is to restrict access to the Balbooa Forms plugin until it can be updated.