CyberRota Analysis
AI-GeneratedThe Vehicle Manager extension for Joomla, versions prior to 6.5.8, is vulnerable to unauthenticated SQL injection due to improper handling of the order_field and order_direction parameters in the ORDER BY clause. This flaw allows attackers to manipulate database queries, potentially leading to data exposure or corruption. Organizations using this extension should prioritize immediate updates to mitigate the risk of exploitation.
Original NVD Description
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 - site/vehiclemanager.php reads the order_field and order_direction sort parameters at three separate anonymous-reachable frontend entry points (category listing, search, and the all-vehicles listing) through a sanitizing function that applies real escaping, but the value is then placed into an unquoted ORDER BY clause, where escaping has no protective effect.