Unauthenticated SQL Injection in Joomla Extension Book Library by Ordasoft
CVE-2026-101110
9.3CRITICAL
What is CVE-2026-101110?
The Joomla extension Book Library by Ordasoft contains a vulnerability that allows for unauthenticated SQL injection. This occurs when the books() function in site/booklibrary.php improperly handles user input sent through the field and direction request parameters. Instead of safely rejecting dangerous inputs, the function uses a flawed keyword blacklist. This permits attackers to exploit the functionality by manipulating the ORDER BY clause without appropriate safeguards, leading to potential data leakage or unauthorized access.
Affected Version(s)
Book Library (Free) extension for Joomla 1.0.0-6.4.6
