天下漏洞,尽知其名
HIGH

CVE-2026-101127 Balbooa Forms 未认证存储型 XSS 漏洞

影响未认证攻击者可注入恶意脚本,管理员查看提交时触发执行

AI 研判

Balbooa Forms 是 Joomla 平台上的表单构建组件。其公开表单上传接口在校验文件扩展名与 MIME 类型后,仍将攻击者提供的原始 multipart 文件名原样存入数据库附件表。当管理员打开相关提交记录时,组件 JavaScript 将文件名直接拼接进 HTML 字符串并赋给 innerHTML,导致存储型 XSS。

影响范围

Balbooa Forms

Balbooa Forms 2.4.3.4 之前的版本受影响,具体受影响版本范围以厂商公告为准。

漏洞详情

漏洞类型为未认证存储型跨站脚本(XSS)。成因是上传接口仅校验扩展名和 MIME 类型,却未对原始文件名做输出编码即持久化存储;前端渲染时又将该文件名直接拼入 HTML 并写入 innerHTML。攻击者无需登录即可上传带恶意文件名的附件,随后通过匿名提交将其关联到新提交记录,待管理员查看时脚本在后台上下文中执行。

利用条件与风险

利用无需认证,仅需能访问公开表单上传与提交接口;管理员查看提交记录即触发,可导致会话劫持或后台操作被冒用,实战风险较高。

修复建议

升级 Balbooa Forms 至 2.4.3.4 或更高版本;临时可对上传文件名进行严格过滤与转义,并在前端渲染时改用 textContent 等安全方式替代 innerHTML。

原始情报

Joomla Extension – balbooa.com – Unauthenticated upload filename stored XSS in Balbooa Forms < 2.4.3.4 – The public form upload endpoint validates the uploaded file's extension and detected MIME type, but stores the attacker-supplied original multipart filename verbatim in `#__baforms_submissions_attachments.name`. A later anonymous form submission associates that temporary attachment with the newly created submission. When an administrator opens the submission, the component's JavaScript retrieves the stored attachment record and concatenates `file.name` directly into an HTML string. The complete string is assigned to `innerHTML`.