Impact
A SQL injection flaw exists in the mod_osgallery_search component where the searchText request parameter is read with an insufficient Joomla filter, allowing arbitrary SQL code to be embedded into a LIKE clause. Because the parameter is used without escaping, an attacker can inject a UNION SELECT and retrieve sensitive database information. The weakness falls under CWE-89, entailing a severe compromise of confidentiality.
Affected Systems
The vulnerability affects installations of the OrdaSoft Joomla Gallery extension for Joomla, both free and paid versions, on any Joomla instance running a version of the extension earlier than 6.2.7. Any site that has this extension deployed is potentially exposed.
Risk and Exploitability
With a CVSS score of 9.3, this flaw is deemed critical; the EPSS score is currently not available, and the vulnerability is not listed in the CISA KEV catalog. The endpoint is publicly accessible and requires no authentication, so an attacker merely needs to send a crafted request to the search box. Successful exploitation would enable unauthorized reading of arbitrary database tables, exposing user credentials, site content, and potentially other sensitive data. The combination of a public entry point and high severity underlines the urgent need for remediation.
OpenCVE Enrichment