Unauthenticated SQL Injection in Joomla Extension Book Library by Ordasoft
CVE-2026-101110

9.3CRITICAL

Key Information:

Vendor
CVE Published:
28 September 2026

What is CVE-2026-101110?

The Joomla extension Book Library by Ordasoft contains a vulnerability that allows for unauthenticated SQL injection. This occurs when the books() function in site/booklibrary.php improperly handles user input sent through the field and direction request parameters. Instead of safely rejecting dangerous inputs, the function uses a flawed keyword blacklist. This permits attackers to exploit the functionality by manipulating the ORDER BY clause without appropriate safeguards, leading to potential data leakage or unauthorized access.

Affected Version(s)

Book Library (Free) extension for Joomla 1.0.0-6.4.6

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ala Arfaoui
.