Unauthenticated SQL Injection in Vehicle Manager by Ordasoft
CVE-2026-101108
9.3CRITICAL
What is CVE-2026-101108?
The Vehicle Manager extension by Ordasoft contains an unauthenticated SQL injection vulnerability that can be exploited through three public entry points: category listing, search, and all-vehicles listing. Despite employing a sanitizing function for the order_field and order_direction parameters, the final placement of these parameters within an unquoted ORDER BY clause renders the escaping ineffective. This can potentially allow attackers to manipulate the database query, leading to unauthorized access to sensitive data.
Affected Version(s)
Vehicle Manager (Free) extension for Joomla 1.0.0-6.5.7
