CVE-2026-101127: Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4
Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4 - The public form upload endpoint validates the uploaded file's extension and detected MIME type, but stores the attacker-supplied original multipart filename verbatim in #baformssubmissionsattachments.name. A later anonymous form submission associates that temporary attachment with the newly created submission. When an administrator opens the submission, the component's JavaScript retrieves the stored attachment record and concatenates file.name directly into an HTML string. The complete string is assigned to innerHTML.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Sites using Balbooa Forms versions earlier than 2.4.3.4 are exposed where an attacker can reach a public form upload endpoint and an administrator later opens the associated submission.
What does an attacker need to exploit it?
The attacker needs to submit an upload through the public form endpoint using a crafted multipart filename, then associate the temporary attachment with a form submission. The file itself must pass the endpoint's extension and detected-MIME-type validation.
When is the malicious script triggered?
The payload is triggered when an administrator opens the affected form submission. The component retrieves the stored attachment name and inserts it into the page through innerHTML.
Does file-type validation prevent this attack?
No. The upload endpoint validates the file extension and detected MIME type, but the vulnerability is in storing and later rendering the attacker-controlled original filename.