Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-102425 — GUI scanner and exploit for CVE-2026-102425, an unauthenticated RCE in Balbooa Forms (com_baforms) via PHP shortcode injection, with mass scanning and shell upload. | Kitploit
Tools/GitHubGitHub/tonydelouvre/cve-2026-102425
Vulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationPost-ExploitationWeb SecurityPenetration TestingUtilities & FrameworksPayload DevelopmentRemote Access Trojan
GitHub
52 days agoNot yet reviewed
tonydelouvre/cve-2026-102425

CVE-2026-102425

GUI scanner and exploit for CVE-2026-102425, an unauthenticated RCE in Balbooa Forms (com_baforms) via PHP shortcode injection, with mass scanning and shell upload.

View Repository

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Content not available in the requested language. Showing English version.

🖥️ BAForms-RCE — CVE-2026-102425 GUI

Dark-neon GUI scanner/exploit untuk CVE-2026-102425 — Balbooa Forms (com_baforms) 1.0.0–2.4.3.3: Unauthenticated RCE via field shortcode injection pada PHP-after-submission action (eval()).

Implementasi GUI mandiri (standalone) — ditulis ulang dari nol berdasarkan mekanisme yang dipublikasikan di advisory resmi. Bukan wrapper CLI pihak lain.

CVECVE-2026-102425 (PUBLISHED 2026-09-29, CNA: Joomla! Project)
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-102425
Komponencom_baforms (Balbooa Forms)
Affected1.0.0 – 2.4.3.3 (fix ≥ 2.4.3.4)
CWECWE-94 (Code Injection)
CVSS 4.09.5 Critical — CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

⚡ Fitur

  • Single URL & Mass list (file .txt, satu URL per baris)
  • Check — deteksi com_baforms, versi dari manifest, form publik (loadAjaxForm / embed), kandidat exploitable
  • Exploit — field shortcode breakout (" ;echo MARKER;//), verifikasi marker, opsi drop uploader (up.php) + verifikasi web-visible (shell_url)
  • LAB TEST — mock server lokal yang mensimulasikan eval() shortcode, 100% aman untuk uji payload
  • Browse… — pemilih file list via dialog
  • Export CSV — semua hasil (check/exploit/lab) ke satu file CSV
  • hits.txt / exploited.txt — output mass otomatis
  • Multithread + timeout + progress bar + log berwarna
  • Tema dark neon 🟢

GUI

📦 Instalasi

git clone https://github.com/tonydelouvre/CVE-2026-102425
cd CVE-2026-102425
pip install -r requirements.txt
python main.py

Python 3.9+. Windows/Linux/macOS.

🚀 Cara Pakai

  1. Jalankan python main.py
  2. Masukkan URL target (single) atau klik Browse… untuk file list (mass)
  3. Pilih aksi: Check (aman, hanya deteksi) atau Exploit
  4. Belum yakin payload-nya jalan? Klik ⚡ LAB TEST — uji lokal tanpa menyentuh host nyata
  5. Setelah scan selesai, klik 💾 Export CSV atau ambil hits.txt / exploited.txt

⚠️ Authorized security testing only. Gunakan hanya pada sistem yang Anda miliki atau punya izin tertulis untuk menguji. Penyalahgunaan adalah tanggung jawab hukum Anda sendiri.

🧪 Mekanisme (ringkas)

Balbooa Forms mengizinkan admin mendefinisikan PHP yang dieksekusi setelah form disubmit. PHP tersebut bisa berisi field shortcode yang diganti dengan nilai mentah yang disubmit visitor sebelum eval() — tanpa escaping. Exploitable ketika:

  1. Versi < 2.4.3.4
  2. Ada form publik memakai action PHP-after-submission
  3. Shortcode field berada di dalam string PHP double-quoted → breakout klasik ";echo …;//

CVSS AT:P berarti konfigurasi rentan (item 2–3) harus ada — install komponen saja tidak cukup.

🩹 Remediasi

  1. Upgrade Balbooa Forms ke 2.4.3.4+
  2. Hapus action PHP-after-submission yang memakai field/URL shortcode sampai patch terpasang
  3. Aktifkan reCAPTCHA pada form publik
  4. Audit images/baforms/uploads/, form, dan akun admin

📚 Referensi

  • PoCbit — CVE-2026-102425
  • mysites.guru — Balbooa Forms advisories

📄 License

MIT — lihat LICENSE.

Download Tool