SQL Injection Vulnerability in OrdaSoft Joomla CCK by OrdaSoft
CVE-2026-102428
9.3CRITICAL
What is CVE-2026-102428?
An unauthenticated SQL injection vulnerability exists in the OrdaSoft Joomla CCK, where the order column for records is derived from user input and is not adequately validated. This oversight allows attackers to manipulate SQL queries, potentially compromising database integrity and exposing sensitive information. It is crucial for users of versions prior to 8.3.16 to assess their risk and apply necessary updates to safeguard their systems.
Affected Version(s)
OrdaSoft Joomla CCK 1.0.0-8.3.15
