Joomla 扩展 - ordasoft.com - Vehicle Manager(免费版)< 6.5.8 中存在反射型跨站脚本漏洞。在公开的车辆详情页面(task=view)中,系统会将 title 请求参数的值直接输出到一个双引号包裹的 HTML 属性中,且未进行任何形式的输出编码。如果参数中包含双引号字符,将会闭合该 HTML 属性,从而允许任意标记(包括 标签)被注入到页面中。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ordasoft.com | Vehicle Manager (Free) extension for Joomla | 1.0.0-6.5.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ordasoft.com | Vehicle Manager (Free) extension for Joomla | 1.0.0-6.5.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100752 | 9.3 CRITICAL | Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Fr |
| CVE-2026-101110 | 9.3 CRITICAL | Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6 |
| CVE-2026-101108 | 9.3 CRITICAL | Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) |
| CVE-2026-100753 | 5.3 MEDIUM | Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (F |
| CVE-2026-101111 | 5.3 MEDIUM | Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) < |
No comments yet