Back

MEDIUM

Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2.4.3.4

Published Sep 29, 2026

Description

Joomla Extension - balbooa.com - Unauthorized Deletion of Attachments in Balbooa Forms < 2.4.3.4 - The public removeTmpAttachment action accepts an integer attachment ID and deletes the matching database row and file. The controller verifies a Joomla session token, but the model does not bind that ID to the session that uploaded the file, the current user, the form, the upload field, or the temporary state. Any guest can obtain a token for their own session, so the token prevents CSRF but does not authorize the target object.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Joomla
Published Sep 29, 2026
Updated Sep 30, 2026
Reserved Sep 28, 2026
CISA Vulnrichment
Updated Sep 30, 2026
NVD
Status Awaiting Analysis
Modified Sep 29, 2026
Red Hat
Severity n/a
Public date n/a