CVE-2026-102424 Balbooa Forms 未认证路径遍历漏洞
影响未认证攻击者可读取服务器任意文件
Balbooa Forms 是 Joomla 平台上的表单扩展组件。在 2.4.3.4 之前的版本中,组件在处理公开表单提交的 upload 字段状态时,信任访客可控的 JSON 数据,未对文件名做路径规范化与目录限制,导致未认证的路径遍历漏洞。攻击者可借此读取 Joomla 进程可访问的任意本地文件。
影响范围
Balbooa Forms 2.4.3.4 之前的版本,具体受影响版本范围以官方公告为准。
漏洞详情
漏洞类型为路径遍历(Path Traversal)。组件在公开表单提交时接受访客可控的 upload 字段 JSON,对其中看似数字的 id 直接信任其 filename,将其拼接在配置的上传目录之下并加入本地附件路径数组,未校验附件归属、会话、表单字段,也未做路径规范化或目录包含限制。当表单启用自动回复并勾选附带上传文件时,组件会把这些本地路径作为邮件附件发送到访客提交的邮箱,攻击者提交不存在的数字 ID 加 ../../../../configuration.php 之类的遍历文件名即可获取任意可读文件。
利用条件与风险
利用前提是目标表单启用了自动回复和附带上传文件选项,且攻击者可提交公开表单。实战中未认证攻击者可远程读取配置文件等敏感信息,风险较高。
修复建议
建议升级 Balbooa Forms 至 2.4.3.4 或更高版本。临时缓解措施为关闭表单的自动回复或附带上传文件选项,并限制上传目录权限,具体以官方公告为准。
Joomla Extension – balbooa.com – Unauthenticated path traversal exfiltrates local files through auto-reply attachments in Balbooa Forms < 2.4.3.4 – Balbooa Forms accepts upload-field state as Guest-controlled JSON during public form submission. For every object whose `id` merely looks numeric, the component trusts the supplied `filename`, concatenates it below the configured upload directory, and adds the result to an array of local attachment paths. It does not load the referenced attachment row, verify ownership/session/form/field, require that the ID exists, canonicalize the path, or enforce containment. If the form's normal “auto reply” and “attach uploaded files” options are enabled, the component sends those local paths as email attachments to the address submitted in an email field. A Guest can therefore submit a nonexistent numeric ID plus a traversal filename such as `../../../../configuration.php` and receive any file readable by the Joomla process.