PT-2026-95995 · Ordasoft · Ordasoft Joomla Gallery

·

CVE-2026-88855

·

Published

2026-09-20

·

Updated

2026-09-20

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions OrdaSoft Joomla Gallery versions prior to 6.2.7
Description An issue exists where the saveGallery() function passes form data through a custom parser into the Joomla Input object. The data is subsequently read using ARRAY and STRING filter types, which do not sanitize SQL content. This allows an authenticated user with core.manage permissions to perform SQL injection by manipulating the category names[], catOrderIds, and image-ordering fields, as these values are concatenated directly into SQL queries without quoting or integer casting. This can lead to full read and write access to the database, including the extraction of password hashes from the # users table via UNION-based techniques.
Recommendations Update OrdaSoft Joomla Gallery to version 6.2.7 or later.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-88855

Affected Products

Ordasoft Joomla Gallery