Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-101110: Joomla Book Library extension lets attackers change data order

CVE-2026-101110 · published 4 days ago
Summary

The free Book Library add‑on for Joomla can be tricked into running a database command that changes how book listings are sorted. An attacker can send specially crafted requests without logging in to manipulate the query and potentially view or alter information. Update the extension to version 6.4.6 or later, or remove it if you do not need the feature.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
ordasoft.com book library (free) extension for joomla 1.0.0-6.4.6
Original advisory text
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s books() function reads the field and direction request parameters and passes each through a function called protectInjectionWithoutQuote(), whose only real protection is a keyword blacklist that, on detecting the literal substring select, wraps the value in $db->quote() instead of rejecting it. The value is then concatenated directly into an unquoted ORDER BY clause, a position where quoting provides no protection at all. Reaching the vulnerable code path requires two conditions: a first request to prime session-stored sort defaults, and a trailing decoy comment (-- xselect) that satisfies the blacklist’s substring check without altering the payload’s effect.
References
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-89SQL Injection
Timeline
Published28 Sep 2026
Updated2 Oct 2026
First seen28 Sep 2026
Sources
CVE-2026-101110 · MITRE
Track software like this
Free during beta