PT-2026-95995 · Ordasoft · Ordasoft Joomla Gallery
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
OrdaSoft Joomla Gallery versions prior to 6.2.7
Description
An issue exists where the
saveGallery() function passes form data through a custom parser into the Joomla Input object. The data is subsequently read using ARRAY and STRING filter types, which do not sanitize SQL content. This allows an authenticated user with core.manage permissions to perform SQL injection by manipulating the category names[], catOrderIds, and image-ordering fields, as these values are concatenated directly into SQL queries without quoting or integer casting. This can lead to full read and write access to the database, including the extraction of password hashes from the # users table via UNION-based techniques.Recommendations
Update OrdaSoft Joomla Gallery to version 6.2.7 or later.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ordasoft Joomla Gallery