Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-101110: Joomla Book Library extension lets attackers change data order
CVE-2026-101110 · published 4 days ago
Summary
The free Book Library add‑on for Joomla can be tricked into running a database command that changes how book listings are sorted. An attacker can send specially crafted requests without logging in to manipulate the query and potentially view or alter information. Update the extension to version 6.4.6 or later, or remove it if you do not need the feature.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| ordasoft.com | book library (free) extension for joomla | 1.0.0-6.4.6 |
Original advisory text
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s books() function reads the field and direction request parameters and passes each through a function called protectInjectionWithoutQuote(), whose only real protection is a keyword blacklist that, on detecting the literal substring select, wraps the value in $db->quote() instead of rejecting it. The value is then concatenated directly into an unquoted ORDER BY clause, a position where quoting provides no protection at all. Reaching the vulnerable code path requires two conditions: a first request to prime session-stored sort defaults, and a trailing decoy comment (-- xselect) that satisfies the blacklist’s substring check without altering the payload’s effect.
References
- https://www.ordasoft.com/ product
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-89SQL Injection
Timeline
Published28 Sep 2026
Updated2 Oct 2026
First seen28 Sep 2026
Track software like this
Free during beta