Balbooa Joomla Forms Builder 2.0.6 SQL Injection Unauthenticated
41Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 8.8epss 0.3%
exploitation probability
0.3%top 76% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Balbooa Joomla Forms Builder 2.0.6 contains an unauthenticated SQL injection vulnerability in the form submission handler that allows remote attackers to execute arbitrary SQL queries. Attackers can send POST requests to the com_baforms component with malicious JSON payloads in the 'id' field parameter to extract sensitive database information.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Affected products
Balbooa · Balbooa Joomla Forms Builderpublic PoCs found — 1
cve_referencewww.exploit-db.com/exploits/50447unverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.