Critical 9.3

Joomla Vehicle Manager SQLi leaks database (CVE-2026-101108) [PoC]

CVE-2026-101108

By Yazoul AI · automated

CVE-2026-101108: Joomla Vehicle Manager (Free) before 6.5.8 unauthenticated SQL injection leaks database contents (CVSS 9.3). Update to 6.5.8 now.

Exploitation confirmed - public proof-of-concept - CVE-2026-101108 is a critical unauthenticated SQL injection in the Joomla Vehicle Manager (Free) component before version 6.5.8 that lets any anonymous visitor read the site’s entire database, including administrator credential hashes. Update to 6.5.8 immediately.

Overview

The Vehicle Manager (Free) extension, published by ordasoft.com for Joomla, exposes three anonymous-reachable frontend entry points: the category listing, the search view, and the all-vehicles listing. Each of these passes the order_field and order_direction sort parameters through a sanitizing function that performs genuine escaping. The escaped value is then inserted into an unquoted ORDER BY clause, where escaping has no protective effect. Attackers can therefore inject arbitrary SQL through a parameter that looks safely handled.

The vulnerable logic lives in site/vehiclemanager.php. Because no authentication, account, or user interaction is required, the attack surface is the public internet: any crawler or scanner can reach these endpoints. A working proof-of-concept is public, which lowers the bar from skilled researcher to script-kiddie tooling.

Impact

Successful exploitation yields full read access to the underlying Joomla database. That typically includes the #__users table, where Joomla stores password hashes, email addresses, and privilege levels. With those hashes in hand, an attacker can attempt offline cracking, pivot to the administrator panel, and from there install a webshell or backdoor. The CVSS score of 9.3 reflects network reachability, low complexity, no privileges, and no user interaction.

Even where hashes resist cracking, leaked emails fuel phishing and credential-stuffing campaigns against the site’s staff and customers. Vehicle dealership and rental sites running this component also hold inventory records, booking data, and customer contact details, all of which become readable.

Remediation and Mitigation

  1. Update the Vehicle Manager (Free) component to 6.5.8 or later. This is the only complete fix.
  2. If you cannot patch immediately, disable the three affected frontend views (category listing, search, all-vehicles listing) or unpublish the component entirely until you can update.
  3. Deploy a web application firewall rule that blocks SQL metacharacters in the order_field and order_direction parameters on vehiclemanager routes.
  4. Rotate Joomla administrator passwords and any database credentials exposed to the site, then audit #__users and access logs for signs of enumeration.
  5. Check your Joomla extension list for other ordasoft components, since shared helper patterns may repeat the same mistake.

If you discover evidence of data theft, breach reports are available at breach reports, and ongoing coverage is at security news.

Security Insight

This case shows why escaping is not a universal sanitizer: the developer applied a real, functioning escape routine, but placed the escaped value into a context where quoting is the actual defense. The same class of error keeps appearing in Joomla extension ecosystems, where small vendors reuse a single input helper across contexts without verifying that the destination is quoted. Buyers of low-cost commercial extensions effectively inherit that vendor’s threat model, and the pattern suggests component marketplaces need mandatory sort-parameter review before listing.

Further Reading

Share:

Never miss a critical vulnerability

Get real-time security alerts delivered to your preferred platform.

Public PoC References

Unverified third-party code

These repositories are publicly listed on GitHub and have not been audited by Yazoul Security. They may contain malware, backdoors, destructive payloads, or operational security risks (telemetry, exfiltration). Treat them as hostile binaries. Inspect source before execution. Run only in isolated, disposable lab environments (offline VM, no credentials, no production data).

Authorized use only. This information is provided for defensive research, detection engineering, and patch validation. Using exploit code against systems you do not own or do not have explicit written permission to test is illegal in most jurisdictions and violates Yazoul's terms of use.

Repository Stars
murrez/CVE-2026-101108

CVE-2026-101108 PoC: OrdaSoft Joomla Vehicle Manager (Free) <=6.5.7 unauth SQLi — order_field/order_direction unquoted ORDER BY (com_vehiclemanager). Colored check + mass exploit, CVSS 9.3. https://po

★ 0

Showing 1 of 1 known references. Source: nomi-sec/PoC-in-GitHub.

Related Advisories

Never Miss a Critical Alert

CVE advisories, breach reports, and threat intel — delivered daily to your inbox.