Joomla Vehicle Manager SQLi leaks database (CVE-2026-101108) [PoC]
CVE-2026-101108
CVE-2026-101108: Joomla Vehicle Manager (Free) before 6.5.8 unauthenticated SQL injection leaks database contents (CVSS 9.3). Update to 6.5.8 now.
Exploitation confirmed - public proof-of-concept - CVE-2026-101108 is a critical unauthenticated SQL injection in the Joomla Vehicle Manager (Free) component before version 6.5.8 that lets any anonymous visitor read the site’s entire database, including administrator credential hashes. Update to 6.5.8 immediately.
Overview
The Vehicle Manager (Free) extension, published by ordasoft.com for Joomla, exposes three anonymous-reachable frontend entry points: the category listing, the search view, and the all-vehicles listing. Each of these passes the order_field and order_direction sort parameters through a sanitizing function that performs genuine escaping. The escaped value is then inserted into an unquoted ORDER BY clause, where escaping has no protective effect. Attackers can therefore inject arbitrary SQL through a parameter that looks safely handled.
The vulnerable logic lives in site/vehiclemanager.php. Because no authentication, account, or user interaction is required, the attack surface is the public internet: any crawler or scanner can reach these endpoints. A working proof-of-concept is public, which lowers the bar from skilled researcher to script-kiddie tooling.
Impact
Successful exploitation yields full read access to the underlying Joomla database. That typically includes the #__users table, where Joomla stores password hashes, email addresses, and privilege levels. With those hashes in hand, an attacker can attempt offline cracking, pivot to the administrator panel, and from there install a webshell or backdoor. The CVSS score of 9.3 reflects network reachability, low complexity, no privileges, and no user interaction.
Even where hashes resist cracking, leaked emails fuel phishing and credential-stuffing campaigns against the site’s staff and customers. Vehicle dealership and rental sites running this component also hold inventory records, booking data, and customer contact details, all of which become readable.
Remediation and Mitigation
- Update the Vehicle Manager (Free) component to 6.5.8 or later. This is the only complete fix.
- If you cannot patch immediately, disable the three affected frontend views (category listing, search, all-vehicles listing) or unpublish the component entirely until you can update.
- Deploy a web application firewall rule that blocks SQL metacharacters in the
order_fieldandorder_directionparameters onvehiclemanagerroutes. - Rotate Joomla administrator passwords and any database credentials exposed to the site, then audit
#__usersand access logs for signs of enumeration. - Check your Joomla extension list for other ordasoft components, since shared helper patterns may repeat the same mistake.
If you discover evidence of data theft, breach reports are available at breach reports, and ongoing coverage is at security news.
Security Insight
This case shows why escaping is not a universal sanitizer: the developer applied a real, functioning escape routine, but placed the escaped value into a context where quoting is the actual defense. The same class of error keeps appearing in Joomla extension ecosystems, where small vendors reuse a single input helper across contexts without verifying that the destination is quoted. Buyers of low-cost commercial extensions effectively inherit that vendor’s threat model, and the pattern suggests component marketplaces need mandatory sort-parameter review before listing.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Public PoC References
Unverified third-party code
These repositories are publicly listed on GitHub and have not been audited by Yazoul Security. They may contain malware, backdoors, destructive payloads, or operational security risks (telemetry, exfiltration). Treat them as hostile binaries. Inspect source before execution. Run only in isolated, disposable lab environments (offline VM, no credentials, no production data).
Authorized use only. This information is provided for defensive research, detection engineering, and patch validation. Using exploit code against systems you do not own or do not have explicit written permission to test is illegal in most jurisdictions and violates Yazoul's terms of use.
| Repository | Stars |
|---|---|
| murrez/CVE-2026-101108 CVE-2026-101108 PoC: OrdaSoft Joomla Vehicle Manager (Free) <=6.5.7 unauth SQLi — order_field/order_direction unquoted ORDER BY (com_vehiclemanager). Colored check + mass exploit, CVSS 9.3. https://po | ★ 0 |
Showing 1 of 1 known references. Source: nomi-sec/PoC-in-GitHub.
Related Advisories
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend property-listin...
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s books() function reads the field and direction request parameters and passes eac...
Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection vulnerability in video search functionality and sorting allowed attackers to i...
YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a defau...