OrdaSoft Simple Membership SQLi (CVE-2026-102782): checkLoginPass login Param
Admin · October 9, 2026 · 10 views
Another OrdaSoft surface—different bug
OrdaSoft Simple Membership (com_simplemembership) is separate from OS CCK upload RCE and order-by SQLi. CVE-2026-102782 is unauthenticated SQL injection on task=checkLoginPass via the login parameter—CVSS 4.0 9.3 Critical, fixed in ≥ 7.4.0.
Joomla’s input filter strips HTML but does not neutralize SQL metacharacters before the value is concatenated into a query. Public PoCs use error-based extractvalue and read ~leak~ from error bodies (often HTTP 500).
Catalog: CVE-2026-102782 on pocbit.org. Repository: murrez/CVE-2026-102782.
Endpoint pattern:
index.php?option=com_simplemembership&task=checkLoginPass&format=raw&login=
Subdirectory installs: pass the Joomla base including path (e.g. https://site.tld/simplemembership).
Defender checklist
| # | Action | Detail |
|---|--------|--------|
| 1 | Inventory Simple Membership version | Extension manager / manifest |
| 2 | Upgrade to ≥ 7.4.0 | Same maintenance window as other OrdaSoft components |
| 3 | Log review | checkLoginPass with odd login payloads |
| 4 | DB hygiene | Assume users table read if exploited—rotate privileged passwords |
| 5 | WAF (bridge) | Rate-limit com_simplemembership + checkLoginPass |
Cross-read: Joomla security checklist (2026), SQL injection types and prevention.
Discovery (your assets)
body="com_simplemembership" && body="ordasoft"
body="task=checkLoginPass"
FOFA hits require --mode check on authorized targets—version alone is insufficient.
Patch validation
Joomla lab with < 7.4.0, run PoC check then controlled exploit with custom --subquery. Upgrade and repeat. See CVE PoC testing step-by-step.
FAQ
We only use Simple Membership admin UI—safe?
Front-end checkLoginPass may still be reachable anonymously—verify routing, then patch.
Same as JCTables JSON API?
No—JCTables is Joomcode com_jctables, different tasks and CNA context.
Bottom line
Treat OrdaSoft as multiple CVE trains—Simple Membership 7.4.0+ is mandatory on any Joomla site running membership login AJAX.