Impact
The vulnerability allows an attacker who can reach the front‑end of a Joomla site to inject arbitrary SQL through the order_field and order_direction parameters used by Vehicle Manager. Because these parameters are interpolated into an ORDER BY clause without proper quoting, an attacker can modify the query, potentially reading sensitive data, modifying entries, or causing a database error. The flaw is unauthenticated and exploitable over the public web, so any visitor can trigger it.
Affected Systems
This flaw is present in the ordasoft.com Vehicle Manager (Free) extension for Joomla, versions prior to 6.5.8. The extension is a free add‑on installed under the /vehiclemanager.php endpoint.
Risk and Exploitability
The CVSS score of 9.3 categorizes the flaw as critical. Because no authentication is required, the exploit can be launched by any web user. Although an EPSS score is not available, the high CVSS indicates that the vulnerability is severe. The flaw is not currently listed in the CISA KEV catalog, but the straightforward query manipulation indicates that attackers could develop a custom payload without extensive effort.
OpenCVE Enrichment