{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3abalbooaforms/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:balbooa:forms:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-102425"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Balbooa Forms (\u003c 2.4.3.4)"],"_cs_severities":["critical"],"_cs_tags":["remote-code-execution","cve-2026-102425","joomla","web-application"],"_cs_type":"advisory","_cs_vendors":["Balbooa"],"content_html":"\u003cp\u003eCVE-2026-102425 is a critical vulnerability (CVSS 9.5) affecting the Balbooa Forms extension (com_baforms) for Joomla, versions 1.0.0 through 2.4.3.3. The flaw is rooted in how the component processes PHP code configured to run after a form submission. Administrators can define PHP snippets that include form-field shortcodes; however, the component fails to sanitize these values before passing them to an eval() function. An unauthenticated remote attacker can supply malicious input via a public form submission, breaking out of a double-quoted string to execute arbitrary PHP code on the server.\u003c/p\u003e\n\u003cp\u003eThis vulnerability requires specific configuration: the site must have a public form that utilizes the \u0026quot;PHP-after-submission\u0026quot; feature containing field or URL shortcodes. Because a functional exploit proof-of-concept is publicly available, organizations using affected versions of Balbooa Forms are at immediate risk of compromise.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker discovers a Joomla site running an vulnerable version of com_baforms (v1.0.0 - 2.4.3.3).\u003c/li\u003e\n\u003cli\u003eAttacker probes the target by sending a GET request to index.php with the task=form.loadAjaxForm parameter to identify form IDs.\u003c/li\u003e\n\u003cli\u003eAttacker identifies a public form that utilizes the \u0026quot;PHP-after-submission\u0026quot; action.\u003c/li\u003e\n\u003cli\u003eAttacker constructs a malicious payload designed to break out of the PHP double-quoted string (e.g., \u0026quot;; system('id'); //).\u003c/li\u003e\n\u003cli\u003eAttacker sends a POST request to the form action with task=form.message containing the malicious payload in a form field.\u003c/li\u003e\n\u003cli\u003eThe server-side component replaces the form shortcode with the attacker's payload and executes the resulting string via eval().\u003c/li\u003e\n\u003cli\u003eThe injected PHP code executes on the web server, allowing for unauthorized command execution or the dropping of webshells such as up.php.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full remote code execution, granting attackers the ability to manipulate the underlying server, exfiltrate data, or establish persistence. Vulnerable sites may be subject to automated mass-exploitation, as evidenced by the availability of scripting tools that support automated scanning and remote shell deployment in common Joomla directories like images/baforms/uploads/.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eImmediately upgrade Balbooa Forms to version 2.4.3.4 or higher to patch CVE-2026-102425.\u003c/li\u003e\n\u003cli\u003eAudit all forms for \u0026quot;PHP-after-submission\u0026quot; actions and temporarily disable those utilizing field or URL shortcodes until the patch is applied.\u003c/li\u003e\n\u003cli\u003eImplement reCAPTCHA on all public-facing forms to mitigate automated exploitation attempts.\u003c/li\u003e\n\u003cli\u003eInspect the directory images/baforms/uploads/ and other common upload paths for unauthorized PHP files or unexpected modifications.\u003c/li\u003e\n\u003cli\u003eDeploy the provided webserver detection rule to identify attempted code injection via form submission tasks.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-30T09:17:40Z","date_published":"2026-09-30T09:17:40Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-102425/","summary":"CVE-2026-102425 is a critical unauthenticated remote code execution vulnerability in the Joomla Balbooa Forms extension allowing code injection via unsanitized field shortcodes.","title":"Critical RCE in Balbooa Forms via Shortcode Injection","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-102425/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:balbooa:forms:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}