天下漏洞,尽知其名
HIGH

CVE-2026-101110 Joomla Book Library 未授权 SQL 注入漏洞

原始情报

Joomla Extension – ordasoft.com – Unauthenticated SQL Injection in Book Library (Free) quote() instead of rejecting it. The value is then concatenated directly into an unquoted ORDER BY clause, a position where quoting provides no protection at all. Reaching the vulnerable code path requires two conditions: a first request to prime session-stored sort defaults, and a trailing decoy comment (– xselect) that satisfies the blacklist’s substring check without altering the payload’s effect.