OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-101110

CRITICAL · CVSS 9.3 EPSS 0.28%

Source: NVD + CISA KEV + EPSS · Published 2026-09-28 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The Joomla Extension from ordasoft.com is vulnerable to unauthenticated SQL injection in the Book Library component versions prior to 6.4.6, specifically within the books() function. Attackers can exploit this vulnerability by manipulating request parameters to execute arbitrary SQL queries, potentially leading to data leakage or unauthorized access. Organizations using this extension should prioritize patching or upgrading to mitigate the risk of exploitation.

CVE
CVE-2026-101110
Severity
CRITICAL
CVSS
9.3
EPSS
0.28%

Original NVD Description

Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s books() function reads the field and direction request parameters and passes each through a function called protectInjectionWithoutQuote(), whose only real protection is a keyword blacklist that, on detecting the literal substring select, wraps the value in $db->quote() instead of rejecting it. The value is then concatenated directly into an unquoted ORDER BY clause, a position where quoting provides no protection at all. Reaching the vulnerable code path requires two conditions: a first request to prime session-stored sort defaults, and a trailing decoy comment (-- xselect) that satisfies the blacklist’s substring check without altering the payload’s effect.