What is CVE-2026-67363?
CVE-2026-67363 is a pre-authentication payment amount tampering vulnerability in the Balbooa Forms extension for Joomla, affecting versions below 2.4.3.2. The `stripeCharges` and `payAuthorize` endpoints accept the charge total from a client-controlled request parameter without server-side recomputation, allowing an attacker to manipulate the payment amount. Upgrading the Balbooa Forms extension to version 2.4.3.2 or later is recommended to fix this issue.
Azərbaycanca: CVE-2026-67363, Balbooa Forms Joomla genişlənməsinin 2.4.3.2-dən əvvəlki versiyalarında aşkar edilmiş, autentifikasiya tələb etməyən ödəniş məbləği manipulyasiyası zəifliyidir. `stripeCharges` və `payAuthorize` endpoint-ləri ödəniş məbləğini birbaşa müştəri tərəfindən idarə olunan sorğu parametrindən götürərək ödəniş qapısına ötürdüyü üçün zərərli istifadəçi ödəniş məbləğini azalda bilər. Bu zəifliyi aradan qaldırmaq üçün Balbooa Forms-u ən azı 2.4.3.2 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: balbooa.com
FAQ2
Which versions of Balbooa Forms are affected by CVE-2026-67363?
This vulnerability exists in versions of the Balbooa Forms Joomla extension below 2.4.3.2.
What action can an attacker perform if CVE-2026-67363 is exploited?
An attacker can reduce the payment amount through a client-controlled parameter in the `stripeCharges` or `payAuthorize` endpoints.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.