Joomla 扩展 - OrdaSoft.com - OrdaSoft Joomla Gallery 扩展(适用于 Joomla < 6.2.7)中存在已认证的、具备特权的 SQL 注入漏洞 该扩展的 函数将通过自研解析器处理的表单数据传入 Joomla 的 Input 对象,随后以 ARRAY 或 STRING 过滤类型读取数据。然而,这两种过滤类型均不对 SQL 内容进行任何净化处理。来自 、 以及图像排序字段的值被直接拼接到 SQL 语句中,既未进行引号转义,也未强制转换为整数类型。因此,任何拥有 权限的已认
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OrdaSoft.com | OrdaSoft Joomla Gallery extension for Joomla | 1.0.0-6.2.6 |
affected |
| OrdaSoft.com | OrdaSoft Joomla Gallery free extension for Joomla | 1.0.0-6.2.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OrdaSoft.com | OrdaSoft Joomla Gallery free extension for Joomla | 1.0.0-6.2.6 | - |
|
| OrdaSoft.com | OrdaSoft Joomla Gallery extension for Joomla | 1.0.0-6.2.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88856 | 9.4 CRITICAL | Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaS |
| CVE-2026-88857 | 9.4 CRITICAL | Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaS |
| CVE-2026-88854 | 9.3 CRITICAL | Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery |
No comments yet