POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
← Blog

OrdaSoft Joomla ORDER BY SQLi (2026): Defender Patch and Detection Guide

Admin · September 29, 2026 · 9 views

Why OrdaSoft extensions dominated September 2026 Joomla headlines

Several OrdaSoft Joomla extensions shipped fixes in the same disclosure window for the same root cause class: user-controlled sort parameters (order_field, order_direction, field, direction) concatenated into unquoted ORDER BY clauses. Attackers do not need administrator credentials—the bugs live on public listing, search, and category views.

If you operate Joomla with OrdaSoft Real Estate Manager, Vehicle Manager, or Book Library, treat this as an inventory and patch campaign, not a single CVE checkbox.

The failure mode in plain language

Modern SQL injection training focuses on quoted strings in WHERE. ORDER BY is different: the database expects identifiers or expressions, not string literals. Code that runs input through a quote escaper—or a weak substring blocklist for the word select—often does nothing useful when the value is pasted directly into ORDER BY.

Worse, some flows require two requests: a “benign” sort primes session defaults, then a second request injects an expression plus a decoy tail (for example a SQL comment containing select) to satisfy a naive filter while the active payload executes.

Impact is not “sort order looks weird.” Successful exploitation can mean database read/write, credential material, and site integrity loss—classic CWE-89 territory with CVSS 9.x scores on several 2026 records.

Map CVEs to products you actually run

Use this table as a starting point for tickets—not as a substitute for reading vendor release notes.

| CVE (2026) | Extension | Fix version (approx.) | Public PoC on pocbit.org | |------------|-----------|------------------------|---------------------------| | CVE-2026-100752 | Real Estate Manager (Free) | 6.7.9+ | /pocs/cve-2026-100752 | | CVE-2026-101108 | Vehicle Manager (Free) | 6.5.8+ | /pocs/cve-2026-101108 | | CVE-2026-101110 | Book Library (Free) | 6.4.7+ | /pocs/cve-2026-101110 |

Related XSS fixes (same release trains) may ship beside SQLi patches—patch the bundle, not one component in isolation.

Defender checklist (copy into your tracker)

| # | Task | Notes | |---|------|-------| | 1 | Export installed components + versions | Joomla admin, Akeeba, or configuration DB | | 2 | Flag any OrdaSoft com_* still below fixed lines | Real estate, vehicle, book library, others from vendor mail | | 3 | Confirm internet exposure of front-end routes | option=com_realestatemanager, com_vehiclemanager, com_booklibrary | | 4 | Upgrade to vendor security releases on a test clone first | Snapshot DB + files | | 5 | Re-test sort URLs after patch | order_field, field, direction should reject garbage safely | | 6 | Review WAF temporarily | Block obvious SQLi on sort params only as bridge control | | 7 | Hunt logs for probing | Error-based SQLi often triggers DB errors in PHP logs |

Cross-link with our broader Joomla security checklist (2026) and extension basics.

Detection and hunting without attacking production

Blue teams can search edge logs and WAF hits for:

  • Repeated requests to index.php?option=com_realestatemanager (or vehicle/book equivalents) with unusual order_field / field values
  • Payload fragments: UPDATEXML, EXTRACTVALUE, CONCAT(0x7e, -- xselect style decoys
  • Spike in 500 responses from MySQL syntax errors on public pages

Asset discovery queries (FOFA/Shodan-style) often start with body="option=com_vehiclemanager"—use results only to confirm inventory, not to scan strangers.

Patch validation in a lab

When a public PoC exists, authorized teams should reproduce in an isolated Joomla VM:

  1. Install the vulnerable extension version on disposable infrastructure.
  2. Run vendor upgrade to the fixed build.
  3. Confirm exploit tooling reports patched or fails closed.

PoCbit hosts mechanism write-ups and Python tooling for several of these CVEs; use them in labs tied to your change record. See safe PoC lab setup and CVE vs PoC testing.

FAQ

We only use one OrdaSoft plugin—do we ignore the others?

No. Shared codebase patterns mean multiple extensions were affected in the same period. Inventory all OrdaSoft packages on the site.

Is disabling sorting enough?

Disabling user-facing sort may reduce exposure on some routes, but upgrade is the durable fix. Temporary WAF rules expire; vendor patches address the parser.

Where do new CVE signals appear?

Watch CVE Detector and your usual Joomla VEL sources. When pocbit publishes a PoC, correlate the CVE ID with your component versions before media pressure drives chaotic patching.

Bottom line

The OrdaSoft ORDER BY wave is a reminder that CMS extensions are part of your attack surface, not accessories. Name the components, match versions to fixed releases, validate in a lab, and patch on a schedule you can defend in an audit—not after the first mass scan hits your logs.