Joomla 扩展 - balbooa.com - Balbooa Forms < 2.4.3.2 中存在预认证 PHP 代码注入漏洞 - CWE-94 / CWE-95 该表单的可选自定义 PHP 提交后处理程序通过 eval() 函数执行。[URL 参数 = X] 短代码被替换为查询参数的原始、未转义值,从而允许未经身份验证的攻击者注入可在服务器端执行的任意 PHP 代码。用于访问该端点所需的 CSRF 令牌本身可通过另一个独立任务匿名获取,因此并不能提供真正的防护。此漏洞的可利用性要求表单必须配置了自定义 P
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| balbooa.com | Balbooa Forms extension for Joomla | 1.0.0-2.4.3.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| balbooa.com | Balbooa Forms extension for Joomla | 1.0.0-2.4.3.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet