CyberRota Analysis
AI-GeneratedThe OrdaSoft Joomla Gallery extension for Joomla versions prior to 6.2.7 is vulnerable to unauthenticated SQL injection due to improper handling of user input in the showSearchResult() and showSearchResultAjax() functions. This flaw allows any unauthenticated user to manipulate SQL queries, potentially exposing sensitive database information. Joomla administrators and developers using this extension should prioritize patching or upgrading to mitigate the risk of data breaches.
Original NVD Description
Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery extension for Joomla < 6.2.7 - The extensions showSearchResult() and showSearchResultAjax() read the textsearch/searchText request parameter with $input->getVar(), which is not a real Joomla filter method and falls through to a filter that strips HTML tags but does not touch quotes or SQL syntax. The value is concatenated directly into a LIKE clause with no escaping. The endpoint requires no login of any kind: mod_osgallery_search is a public, commonly-published search box. Any anonymous site visitor can inject a UNION SELECT and read arbitrary database content.