Joomla 扩展 – balbooa.com – Balbooa Forms(版本低于 2.4.3.2)存在预认证支付金额篡改漏洞。 stripeCharges 和 payAuthorize 两个接口直接从客户端控制的请求参数中获取支付总额,并未经过基于表单配置产品价格的重新计算,便将其转发至支付网关。此外,这两个接口均未实施身份验证或跨站请求伪造(CSRF)检查。因此,未经认证的攻击者可以以任意金额(例如 0.01 美元)购买任何标价商品,并且还可以伪造行项目、数量以及运费信息。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| balbooa.com | Balbooa Forms extension for Joomla | 1.0.0-2.4.3.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| balbooa.com | Balbooa Forms extension for Joomla | 1.0.0-2.4.3.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet