Unauthenticated SQL Injection in Vehicle Manager by Ordasoft
CVE-2026-101108

9.3CRITICAL

Key Information:

Vendor
CVE Published:
28 September 2026

What is CVE-2026-101108?

The Vehicle Manager extension by Ordasoft contains an unauthenticated SQL injection vulnerability that can be exploited through three public entry points: category listing, search, and all-vehicles listing. Despite employing a sanitizing function for the order_field and order_direction parameters, the final placement of these parameters within an unquoted ORDER BY clause renders the escaping ineffective. This can potentially allow attackers to manipulate the database query, leading to unauthorized access to sensitive data.

Affected Version(s)

Vehicle Manager (Free) extension for Joomla 1.0.0-6.5.7

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ala Arfaoui
.