CVE-2026-101112: Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2.4.3.4
Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2.4.3.4 - The public removeTmpAttachment action accepts an integer attachment ID and deletes the matching database row and file. The controller verifies a Joomla session token, but the model does not bind that ID to the session that uploaded the file, the current user, the form, the upload field, or the temporary state. Any guest can obtain a token for their own session, so the token prevents CSRF but does not authorize the target object.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Joomla Extension - balbooa.com - Balbooa Formsto a version that resolves this vulnerability.Fixed in 2.4.3.4
Event History
Frequently Asked Questions
Does exploitation require an authenticated Joomla account or a valid token from the victim?
No. A guest can obtain a Joomla session token for their own session; the token check protects against CSRF but does not authorize the attachment being deleted.
What does an attacker need to target to delete an attachment?
The attacker needs an integer attachment ID. The deletion path does not verify that the attachment belongs to the attacker’s session, user, form, upload field, or temporary upload state.
What is deleted when the action succeeds?
The matching attachment database row and its associated file are deleted.