CVE-2026-101112

LOWCVSS 6.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2.4.3.4 - The public removeTmpAttachment action accepts an integer attachment ID and deletes the matching database row and file. The controller verifies a Joomla session token, but the model does not bind that ID to the session that uploaded the file, the current user, the form, the upload field, or the temporary state. Any guest can obtain a token for their own session, so the token prevents CSRF but does not authorize the target object.

0.0/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-01: 110-01
Referenced assets1 URL
By indicator
Full discourse1 post
  • Ryx@PadhiyarRushi

    Uploaded filename in Balbooa Forms is stored XSS, rendered in the admin view! CVE-2026-101127 (CVSS 8.6): Anonymous submit, malicious filename, admin opens the submission. Same 2.4.3.4 drop! Two siblings on the attachment path: - CVE-2026-101112 deletes any visitor’s temp attachment. - CVE-2026-101126 rewrites attachment names and references on submit. All five are unauth through a public form. https://mysites.guru/vulnerabilities/CVE-2026-102425/ #Cybersecurity #AI #AISecurity #MCP #Claude #GPT #Infosec #Trending #Joomla #XSS #BugBounty

    00031116
    943 followersView on X

Explore more