<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Balbooa Forms (&lt; 2.4.3.4) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/balbooa-forms--2.4.3.4/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 30 Sep 2026 09:17:40 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/balbooa-forms--2.4.3.4/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical RCE in Balbooa Forms via Shortcode Injection</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-102425/</link><pubDate>Wed, 30 Sep 2026 09:17:40 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-102425/</guid><description>CVE-2026-102425 is a critical unauthenticated remote code execution vulnerability in the Joomla Balbooa Forms extension allowing code injection via unsanitized field shortcodes.</description><content:encoded><![CDATA[<p>CVE-2026-102425 is a critical vulnerability (CVSS 9.5) affecting the Balbooa Forms extension (com_baforms) for Joomla, versions 1.0.0 through 2.4.3.3. The flaw is rooted in how the component processes PHP code configured to run after a form submission. Administrators can define PHP snippets that include form-field shortcodes; however, the component fails to sanitize these values before passing them to an eval() function. An unauthenticated remote attacker can supply malicious input via a public form submission, breaking out of a double-quoted string to execute arbitrary PHP code on the server.</p>
<p>This vulnerability requires specific configuration: the site must have a public form that utilizes the &quot;PHP-after-submission&quot; feature containing field or URL shortcodes. Because a functional exploit proof-of-concept is publicly available, organizations using affected versions of Balbooa Forms are at immediate risk of compromise.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker discovers a Joomla site running an vulnerable version of com_baforms (v1.0.0 - 2.4.3.3).</li>
<li>Attacker probes the target by sending a GET request to index.php with the task=form.loadAjaxForm parameter to identify form IDs.</li>
<li>Attacker identifies a public form that utilizes the &quot;PHP-after-submission&quot; action.</li>
<li>Attacker constructs a malicious payload designed to break out of the PHP double-quoted string (e.g., &quot;; system('id'); //).</li>
<li>Attacker sends a POST request to the form action with task=form.message containing the malicious payload in a form field.</li>
<li>The server-side component replaces the form shortcode with the attacker's payload and executes the resulting string via eval().</li>
<li>The injected PHP code executes on the web server, allowing for unauthorized command execution or the dropping of webshells such as up.php.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in full remote code execution, granting attackers the ability to manipulate the underlying server, exfiltrate data, or establish persistence. Vulnerable sites may be subject to automated mass-exploitation, as evidenced by the availability of scripting tools that support automated scanning and remote shell deployment in common Joomla directories like images/baforms/uploads/.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Immediately upgrade Balbooa Forms to version 2.4.3.4 or higher to patch CVE-2026-102425.</li>
<li>Audit all forms for &quot;PHP-after-submission&quot; actions and temporarily disable those utilizing field or URL shortcodes until the patch is applied.</li>
<li>Implement reCAPTCHA on all public-facing forms to mitigate automated exploitation attempts.</li>
<li>Inspect the directory images/baforms/uploads/ and other common upload paths for unauthorized PHP files or unexpected modifications.</li>
<li>Deploy the provided webserver detection rule to identify attempted code injection via form submission tasks.</li>
</ol>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>remote-code-execution</category><category>cve-2026-102425</category><category>joomla</category><category>web-application</category></item></channel></rss>