Book Library SQLi leaks Joomla data, no auth (CVE-2026-101110) [PoC]
CVE-2026-101110
CVE-2026-101110: unauthenticated SQL injection in Joomla Book Library (Free) below 6.4.6 lets attackers read the site database. Update to 6.4.6 now.
Exploitation confirmed - public proof-of-concept - CVE-2026-101110 is a critical unauthenticated SQL injection in the Joomla Book Library (Free) extension before version 6.4.6 that lets any remote attacker read data straight out of the site’s database, including Joomla user records and password hashes. No account is required and there is no user interaction; updating to 6.4.6 removes the flaw.
Overview
Book Library (Free), published by ordasoft.com, is a Joomla extension that renders book catalogs on a site. A request handled by site/booklibrary.php reaches the books() function, which reads the field and direction request parameters so it can sort the listing. Each value is passed through a helper named protectInjectionWithoutQuote() before use. That helper does not validate the value; it only scans for a small keyword blacklist. When it sees the literal substring select, it wraps the value in $db->quote() instead of rejecting the request.
The failure is that the sanitized value is then concatenated into an ORDER BY clause that is not itself quoted. Quoting a string inside an ORDER BY position changes its meaning but provides no defense, so an attacker can break out of the intended expression and append their own SQL. Two conditions make the path reachable: an initial request that primes session-stored sort defaults, and a trailing decoy comment such as -- xselect that satisfies the blacklist substring check without changing how the payload is interpreted.
Impact
Because the injection point sits in an ORDER BY clause, attackers can use boolean and time-based techniques to extract data row by row. The query runs with the privileges of the Joomla database account, so the reachable data usually includes #__users rows: usernames, email addresses, password hashes, and the secret used to sign session tokens. Recovering that secret lets an attacker forge a valid administrator session and take over the Joomla site. Leaked credentials also fuel credential-stuffing against other services, and the same database account may expose content from other extensions sharing the schema. Public sites running the extension are directly reachable over the network, which is why the CVSS score is 9.3.
Remediation
- Update Book Library (Free) to 6.4.6 or later. The vendor release is the only complete fix; there is no configuration toggle that closes the injection point.
- If you cannot patch immediately, uninstall the extension if it is not in active use, or block requests to
site/booklibrary.phpat your WAF or reverse proxy. - Treat the database as potentially compromised if the site ran an affected version. Rotate the Joomla database password, the
secretvalue inconfiguration.php, and any administrator credentials, then invalidate existing sessions. - Review web server logs for requests carrying
field,direction, or-- xselectpatterns, and monitor for unusualORDER BYfragments reachingindex.php.
Security Insight
Joomla third-party extensions keep producing high-severity SQL injection because developers write bespoke input filters instead of binding parameters, and a keyword blacklist is a filter that fails by design: the -- xselect decoy shows how little effort is needed to satisfy it while leaving the payload intact. The pattern echoes the Balbooa Forms and Joomla custom field SQLi bugs that required the same two-step session priming. It also shows that the “quote it instead of reject it” instinct is dangerous wherever the value lands outside a string literal position, because quoting and escaping only protect data values - not SQL syntax. Site operators should treat extension inventory and update cadence as their real attack surface.
Related coverage: breach reports and security news.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Public PoC References
Unverified third-party code
These repositories are publicly listed on GitHub and have not been audited by Yazoul Security. They may contain malware, backdoors, destructive payloads, or operational security risks (telemetry, exfiltration). Treat them as hostile binaries. Inspect source before execution. Run only in isolated, disposable lab environments (offline VM, no credentials, no production data).
Authorized use only. This information is provided for defensive research, detection engineering, and patch validation. Using exploit code against systems you do not own or do not have explicit written permission to test is illegal in most jurisdictions and violates Yazoul's terms of use.
| Repository | Stars |
|---|---|
| murrez/CVE-2026-101110 CVE-2026-101110 PoC: OrdaSoft Joomla Book Library (Free) <=6.4.6 unauth SQLi — field/direction ORDER BY, session prime + `-- xselect` blacklist bypass (com_booklibrary). Colored check + mass exploit, | ★ 0 |
Showing 1 of 1 known references. Source: nomi-sec/PoC-in-GitHub.
Related Advisories
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend property-listin...
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 - site/vehiclemanager.php reads the order_field and order_direction sort parameters at three separate ...
Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection vulnerability in video search functionality and sorting allowed attackers to i...
YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a defau...