天下漏洞,尽知其名
HIGH

CVE-2026-101112 Balbooa Forms 未授权删除附件漏洞

影响任意访客可删除服务器上的任意上传附件文件

AI 研判

Balbooa Forms 是 Joomla 平台上的表单构建扩展。其公开的 removeTmpAttachment 动作仅校验 Joomla 会话令牌,未将附件 ID 与上传者会话、用户、表单或字段绑定,导致任意访客可删除任意附件。

影响范围

Balbooa Forms

Balbooa Forms 2.4.3.4 之前的版本,具体受影响版本范围暂无更详细的公开信息。

漏洞详情

漏洞类型为越权访问/未授权操作。控制器虽然验证了 Joomla session token,但该 token 仅能防止 CSRF,任何访客都能为自己的会话获取合法 token。模型层未校验附件 ID 是否属于当前会话或用户,因此攻击者可传入任意整数 ID 删除对应数据库记录及文件。

利用条件与风险

利用无需认证,攻击者只需获取自身会话的合法 token 即可发起请求。实战中可批量删除表单上传的临时附件,造成数据丢失或业务中断。

修复建议

官方已在 Balbooa Forms 2.4.3.4 中修复,建议升级至该版本或更高。临时缓解措施暂无公开信息,可考虑限制 removeTmpAttachment 接口访问或加强附件归属校验。

原始情报

Joomla Extension – balbooa.com – Unauthorized Deletion of Attachments in Balbooa Forms < 2.4.3.4 – The public removeTmpAttachment action accepts an integer attachment ID and deletes the matching database row and file. The controller verifies a Joomla session token, but the model does not bind that ID to the session that uploaded the file, the current user, the form, the upload field, or the temporary state. Any guest can obtain a token for their own session, so the token prevents CSRF but does not authorize the target object.