Reflected Cross-Site Scripting in Joomla Extension by Ordasoft
CVE-2026-101111
5.3MEDIUM
What is CVE-2026-101111?
A reflected Cross-Site Scripting (XSS) vulnerability exists in the Book Library extension developed by Ordasoft for Joomla platforms. Specifically, this issue arises in the public book-detail page template, where the application improperly handles user input by echoing the raw title request parameter directly into a double-quoted HTML attribute without any escaping. This misconfiguration allows attackers to craft a malicious URL that could execute arbitrary HTML or JavaScript code within the user's browser, potentially leading to data theft or unauthorized actions. Users of Book Library versions prior to 6.4.6 are advised to update their installations promptly to mitigate this risk.
Affected Version(s)
Book Library (Free) extension for Joomla 1.0.0-6.4.6
