SQL Injection Vulnerability in OrdaSoft Joomla Gallery Extension
CVE-2026-88855

8.6HIGH

What is CVE-2026-88855?

An SQL injection vulnerability exists in the OrdaSoft Joomla Gallery extension prior to version 6.2.7. The extension's saveGallery() method improperly handles user input, allowing an authenticated user with the core.manage permission to manipulate SQL queries. This could lead to unauthorized access to sensitive data, including user password hashes, as SQL commands can directly incorporate unsanitized input. The lack of proper input sanitization poses a significant risk of data breaches and unauthorized database access.

Affected Version(s)

OrdaSoft Joomla Gallery extension for Joomla 1.0.0-6.2.6

OrdaSoft Joomla Gallery free extension for Joomla 1.0.0-6.2.6

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ala Arfaoui
.