CVE-2026-101110
Received Received - Intake

Unauthenticated SQL Injection in Joomla Book Library Extension

Vulnerability report for CVE-2026-101110, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: Joomla! Project

Description

Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s books() function reads the field and direction request parameters and passes each through a function called protectInjectionWithoutQuote(), whose only real protection is a keyword blacklist that, on detecting the literal substring select, wraps the value in $db->quote() instead of rejecting it. The value is then concatenated directly into an unquoted ORDER BY clause, a position where quoting provides no protection at all. Reaching the vulnerable code path requires two conditions: a first request to prime session-stored sort defaults, and a trailing decoy comment (-- xselect) that satisfies the blacklist’s substring check without altering the payload’s effect.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ordasoft book_library to 6.4.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-89 The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated SQL injection vulnerability in the Joomla Book Library extension versions before 6.4.6. The flaw exists in the books() function which processes user-supplied 'field' and 'direction' parameters. These parameters are passed through a weak sanitization function that only checks for the substring 'select' before being used in an unquoted ORDER BY SQL clause, allowing attackers to inject malicious SQL commands.

Detection Guidance

To detect this vulnerability, inspect Joomla sites using the Book Library (Free) extension version below 6.4.6. Check for suspicious ORDER BY clauses in SQL queries targeting site/booklibrary.php. Monitor for requests with parameters like field and direction containing SQL keywords such as select.

Impact Analysis

An attacker could exploit this to execute arbitrary SQL commands on the database, potentially stealing sensitive data, modifying or deleting records, or taking control of the affected Joomla site. The vulnerability requires two steps: first setting session defaults, then sending a specially crafted request with a decoy comment to bypass basic filtering.

Compliance Impact

This vulnerability allows unauthenticated SQL injection, which could lead to unauthorized access to sensitive data. For GDPR, this may result in violations of data confidentiality and integrity requirements. For HIPAA, it could compromise protected health information integrity and availability.

Mitigation Strategies

Immediately update the Book Library (Free) extension to version 6.4.6 or higher. If updating is not possible, disable the extension or restrict access to site/booklibrary.php. Review server logs for signs of exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101110. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart