Medium severityNVD Advisory· Published Sep 29, 2026
CVE-2026-101112
CVE-2026-101112
Description
Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2.4.3.4 - The public removeTmpAttachment action accepts an integer attachment ID and deletes the matching database row and file. The controller verifies a Joomla session token, but the model does not bind that ID to the session that uploaded the file, the current user, the form, the upload field, or the temporary state. Any guest can obtain a token for their own session, so the token prevents CSRF but does not authorize the target object.
Affected products
2- Range: <2.4.3.4
- Range: <2.4.3.4
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.