CVE-2026-101112: Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2.4.3.4

Published Sep 29, 2026
·
Updated

Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2.4.3.4 - The public removeTmpAttachment action accepts an integer attachment ID and deletes the matching database row and file. The controller verifies a Joomla session token, but the model does not bind that ID to the session that uploaded the file, the current user, the form, the upload field, or the temporary state. Any guest can obtain a token for their own session, so the token prevents CSRF but does not authorize the target object.

Affected Software

1 affected component
Balbooa Balbooa Forms<2.4.3.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Joomla Extension - balbooa.com - Balbooa Forms to a version that resolves this vulnerability.

    Fixed in 2.4.3.4

Event History

Sep 29, 2026
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
DescriptionWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Does exploitation require an authenticated Joomla account or a valid token from the victim?

No. A guest can obtain a Joomla session token for their own session; the token check protects against CSRF but does not authorize the attachment being deleted.

2

What does an attacker need to target to delete an attachment?

The attacker needs an integer attachment ID. The deletion path does not verify that the attachment belongs to the attacker’s session, user, form, upload field, or temporary upload state.

3

What is deleted when the action succeeds?

The matching attachment database row and its associated file are deleted.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203