CVE-2026-101111: Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) < 6.4.6
Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Book Library (Free) < 6.4.6 - The public book-detail page template, site/views/viewbook/tmpl/default.php, echoes the raw title request parameter directly into a double-quoted HTML attribute with no escaping function of any kind (echo $REQUEST["title"];). A value containing a double quote closes the attribute early and allows arbitrary HTML/JavaScript to follow.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Ordasoft Book Library (Free) versions earlier than 6.4.6 are affected. The vulnerable code is in the public book-detail page template, so exposure depends on whether that page can be reached by an attacker or victim.
What does an attacker need to exploit it?
An attacker needs to supply a crafted title request parameter to the book-detail page. A double quote in the parameter can terminate the HTML attribute and inject arbitrary HTML or JavaScript.
How can I determine whether my installation is affected?
Check whether Book Library (Free) is below version 6.4.6 and inspect site/views/view_book/tmpl/default.php. An affected template directly outputs $_REQUEST["title"] into a double-quoted HTML attribute without escaping.