CyberRota Analysis
AI-GeneratedThe Joomla Extension from ordasoft.com is vulnerable to unauthenticated SQL injection in the Book Library component versions prior to 6.4.6, specifically within the books() function. Attackers can exploit this vulnerability by manipulating request parameters to execute arbitrary SQL queries, potentially leading to data leakage or unauthorized access. Organizations using this extension should prioritize patching or upgrading to mitigate the risk of exploitation.
Original NVD Description
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s books() function reads the field and direction request parameters and passes each through a function called protectInjectionWithoutQuote(), whose only real protection is a keyword blacklist that, on detecting the literal substring select, wraps the value in $db->quote() instead of rejecting it. The value is then concatenated directly into an unquoted ORDER BY clause, a position where quoting provides no protection at all. Reaching the vulnerable code path requires two conditions: a first request to prime session-stored sort defaults, and a trailing decoy comment (-- xselect) that satisfies the blacklist’s substring check without altering the payload’s effect.