CVE-2026-101127: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in balbooa.com Balbooa Forms extension for Joomla
Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4 - The public form upload endpoint validates the uploaded file's extension and detected MIME type, but stores the attacker-supplied original multipart filename verbatim in `#__baforms_submissions_attachments.name`. A later anonymous form submission associates that temporary attachment with the newly created submission. When an administrator opens the submission, the component's JavaScript retrieves the stored attachment record and concatenates `file.name` directly into an HTML string. The complete string is assigned to `innerHTML`.
AI Analysis
Technical Summary
The Balbooa Forms extension for Joomla (versions 1.0.0 to 2.4.3.3) contains an unauthenticated XSS vulnerability due to improper neutralization of input during web page generation (CWE-79). Specifically, the upload endpoint validates file extensions and MIME types but stores the attacker-controlled original multipart filename verbatim in the database. Later, when an administrator views the submission, the stored filename is concatenated directly into an HTML string assigned to innerHTML without sanitization, allowing execution of arbitrary JavaScript in the administrator's browser.
Potential Impact
An attacker can craft a malicious filename that, when uploaded and later viewed by an administrator, executes arbitrary JavaScript code in the administrator's browser context. This can lead to session hijacking, privilege escalation, or other malicious actions within the Joomla administration interface. The vulnerability requires no authentication to upload the malicious file but requires an administrator to view the submission to trigger the exploit.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a patch is available, administrators should avoid opening form submissions with uploaded files or implement manual sanitization of filenames before display. Monitoring vendor communications for an official fix is recommended.
CVE-2026-101127: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in balbooa.com Balbooa Forms extension for Joomla
Description
Joomla Extension - balbooa.com - Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4 - The public form upload endpoint validates the uploaded file's extension and detected MIME type, but stores the attacker-supplied original multipart filename verbatim in `#__baforms_submissions_attachments.name`. A later anonymous form submission associates that temporary attachment with the newly created submission. When an administrator opens the submission, the component's JavaScript retrieves the stored attachment record and concatenates `file.name` directly into an HTML string. The complete string is assigned to `innerHTML`.
CVSS v4.0
Score 8.6high
Affected software
balbooa.com
Balbooa Forms extension for Joomla
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Balbooa Forms extension for Joomla (versions 1.0.0 to 2.4.3.3) contains an unauthenticated XSS vulnerability due to improper neutralization of input during web page generation (CWE-79). Specifically, the upload endpoint validates file extensions and MIME types but stores the attacker-controlled original multipart filename verbatim in the database. Later, when an administrator views the submission, the stored filename is concatenated directly into an HTML string assigned to innerHTML without sanitization, allowing execution of arbitrary JavaScript in the administrator's browser.
Potential Impact
An attacker can craft a malicious filename that, when uploaded and later viewed by an administrator, executes arbitrary JavaScript code in the administrator's browser context. This can lead to session hijacking, privilege escalation, or other malicious actions within the Joomla administration interface. The vulnerability requires no authentication to upload the malicious file but requires an administrator to view the submission to trigger the exploit.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a patch is available, administrators should avoid opening form submissions with uploaded files or implement manual sanitization of filenames before display. Monitoring vendor communications for an official fix is recommended.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Joomla
- Date Reserved
- 2026-09-28T07:02:41.617Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6abbf52e94a11e1e08e474ca
Added to database: 09/29/2026, 17:28:14 UTC
Last enriched: 09/29/2026, 17:28:53 UTC
Last updated: 09/29/2026, 18:28:02 UTC
Views: 6
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.