Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-28f5-j5p5-xmmw

Опубликовано: 09 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 10
CVSS3: 9.8

Описание

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

EPSS

Процентиль: 99%
0.76066
Высокий

10 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 9.8
nvd
21 день назад

Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

EPSS

Процентиль: 99%
0.76066
Высокий

10 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-434