CyberRota Analysis
AI-GeneratedThe OrdaSoft Joomla CCK extension versions prior to 8.3.16 are vulnerable to an unauthenticated SQL injection due to insufficient validation of the user-provided order column for records. This critical vulnerability allows attackers to execute arbitrary SQL queries, potentially compromising the database and exposing sensitive information. Joomla site administrators and users of the affected extension should prioritize immediate updates to mitigate the risk.
Original NVD Description
Joomla Extension - ordasoft.com - Unauthenticated SQL injection in OrdaSoft Joomla CCK < 8.3.16 - The order column for records was user provided and not properly validated, leading to a SQL injection vector.