Joomla 扩展 - OrdaSoft.com - OrdaSoft Joomla 图库扩展(Joomla < 6.2.7)存在已认证的、具备特权的远程代码执行漏洞 - 该扩展的 updateOSGallery() 函数(可通过 task=update_osgallery 参数访问)会读取 JSON 请求体,并将其中 method 字段的值直接作为实时 PHP 函数调用,同时将 package 字段的值作为该函数的唯一参数传递。该过程中未实施任何白名单机制或 is_callable() 检查。因此,任何接受单个参
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| OrdaSoft.com | OrdaSoft Joomla Gallery extension for Joomla | 1.0.0-6.2.6 |
affected |
| OrdaSoft.com | OrdaSoft Joomla Gallery free extension for Joomla | 1.0.0-6.2.6 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OrdaSoft.com | OrdaSoft Joomla Gallery free extension for Joomla | 1.0.0-6.2.6 | - |
|
| OrdaSoft.com | OrdaSoft Joomla Gallery extension for Joomla | 1.0.0-6.2.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88857 | 9.4 CRITICAL | Joomla Extension - OrdaSoft.com - Authenticated, Privileged Remote Code Execution in OrdaS |
| CVE-2026-88854 | 9.3 CRITICAL | Joomla Extension - OrdaSoft.com - Unauthenticated SQL Injection in OrdaSoft Joomla Gallery |
| CVE-2026-88855 | 8.6 HIGH | Joomla Extension - OrdaSoft.com - Authenticated, Privileged SQL Injection in OrdaSoft Joom |
No comments yet