Joomla 扩展 - ordasoft.com - Book Library(免费版)< 6.4.6 中存在反射型跨站脚本漏洞(Reflected Cross-Site Scripting) 在 Book Library(免费版)版本低于 6.4.6 的 Joomla 扩展中,公共图书详情页模板文件 将未经任何转义处理的原始 请求参数直接输出到一个双引号包裹的 HTML 属性中(代码为: )。攻击者可构造包含双引号的恶意 参数值,从而提前闭合该 HTML 属性,并在其后插入任意 HTML 或 JavaScript
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| ordasoft.com | Book Library (Free) extension for Joomla | 1.0.0-6.4.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ordasoft.com | Book Library (Free) extension for Joomla | 1.0.0-6.4.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100752 | 9.3 CRITICAL | Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Fr |
| CVE-2026-101110 | 9.3 CRITICAL | Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6 |
| CVE-2026-101108 | 9.3 CRITICAL | Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) |
| CVE-2026-100753 | 5.3 MEDIUM | Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (F |
| CVE-2026-101109 | 5.3 MEDIUM | Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Vehicle Manager (Free) |
No comments yet