Unauthenticated SQL Injection in OrdaSoft Real Estate Manager
OrdaSoft Real Estate Manager for Joomla versions 6.7.8 and earlier are vulnerable to unauthenticated SQL injection via the 'order_field' parameter, enabling unauthorized database access and data exfiltration.
CVE search metadata
CVE search record: CVE-2026-100752. KEV: no. Product: Real Estate Manager (<= 6.7.8). Brief: Unauthenticated SQL Injection in OrdaSoft Real Estate Manager. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ordasoft-sqli/
CVE search record: CVE-2026-100753. KEV: no. Product: Real Estate Manager (<= 6.7.8). Brief: Unauthenticated SQL Injection in OrdaSoft Real Estate Manager. Brief link: https://feed.craftedsignal.io/briefs/2026-09-ordasoft-sqli/
OrdaSoft Real Estate Manager (Free), a popular property management extension for Joomla, contains a critical unauthenticated SQL injection vulnerability tracked as CVE-2026-100752. The flaw exists in the component 'com_realestatemanager' (specifically in 'site/realestatemanager.php'), where the 'order_field' parameter is unsafely concatenated into an SQL ORDER BY clause. Because the application lacks allow-listing or proper input validation for this parameter, an unauthenticated attacker can inject arbitrary SQL commands. This can lead to full database enumeration, extraction of sensitive information such as user credentials, and potential administrative compromise of the underlying Joomla instance. A related reflected XSS vulnerability (CVE-2026-100753) was disclosed in the same security update train. Defenders must prioritize upgrading all OrdaSoft components to version 6.7.9 or later, as functional PoC code for this SQL injection is publicly available.
Attack Chain
- Attacker performs discovery to identify Joomla sites running the 'com_realestatemanager' extension using Dorks or automated scanners.
- Attacker verifies the target version by requesting 'site/realestatemanager.php' or checking the manifest file at '/administrator/components/com_realestatemanager/realestatemanager.xml'.
- Attacker crafts a malicious HTTP GET or POST request targeting the 'showCategory' task in 'com_realestatemanager'.
- Attacker injects a payload into the 'order_field' parameter (e.g., using UNION-based or error-based SQL injection techniques).
- The Joomla server processes the malicious input and executes the injected SQL command against the database due to lack of input sanitization.
- The backend database returns query results (e.g., database version, table contents, or user hashes) embedded in the HTTP response.
- Attacker parses the response to exfiltrate database contents or further escalate privileges within the Joomla environment.
Impact
Successful exploitation allows unauthenticated attackers to read arbitrary data from the database, including site configuration, user lists, and password hashes. Given that the extension is used to manage real estate listings and customer data, this poses a significant risk to data privacy and site integrity. Organizations failing to patch are at high risk of full database exfiltration.
Recommendation
- Upgrade OrdaSoft Real Estate Manager to version 6.7.9 or later immediately to patch CVE-2026-100752 and CVE-2026-100753.
- Audit all OrdaSoft Joomla extensions for similar vulnerabilities, as other components in the same vendor suite were patched concurrently.
- Deploy web application firewall (WAF) rules to inspect the 'order_field' parameter in requests to 'com_realestatemanager' for SQL injection patterns (e.g., SELECT, UNION, or comment sequences).
- Use the provided Sigma rule to monitor for malicious injection attempts against the target component.
Immediate actions
Upgrade all OrdaSoft Real Estate Manager instances to 6.7.9 or later
Threat Hunt
Search logs for suspicious order_field parameters containing SQL keywords
Data: web_server_logs
Mitigations
Patch OrdaSoft extensions
CVE-2026-100752
Detection coverage 1
Detects CVE-2026-100752 Exploitation - SQL Injection in OrdaSoft Real Estate Manager
highDetects exploitation attempts against the OrdaSoft Real Estate Manager extension by identifying SQL injection patterns in the order_field parameter.
Detection queries are available on the platform. Get full rules →