PT-2026-95994 · Ordasoft · Ordasoft Joomla Gallery
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
OrdaSoft Joomla Gallery versions prior to 6.2.7
Description
An unauthenticated SQL Injection exists in the OrdaSoft Joomla Gallery extension. The functions
showSearchResult() and showSearchResultAjax() process the textsearch or searchText request parameters using $input->getVar(), which fails to properly filter quotes or SQL syntax. This allows the input to be concatenated directly into a LIKE clause without escaping. Because the mod osgallery search endpoint is public and requires no authentication, an anonymous visitor can use a UNION SELECT statement to read arbitrary database content.Recommendations
Update to version 6.2.7 or later.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ordasoft Joomla Gallery