<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:ordasoft:real_estate_manager:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aordasoftreal_estate_manager/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 29 Sep 2026 00:27:47 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aordasoftreal_estate_manager/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unauthenticated SQL Injection in OrdaSoft Real Estate Manager</title><link>https://feed.craftedsignal.io/briefs/2026-09-ordasoft-sqli/</link><pubDate>Tue, 29 Sep 2026 00:27:47 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-ordasoft-sqli/</guid><description>OrdaSoft Real Estate Manager for Joomla versions 6.7.8 and earlier are vulnerable to unauthenticated SQL injection via the 'order_field' parameter, enabling unauthorized database access and data exfiltration.</description><content:encoded><![CDATA[<p>OrdaSoft Real Estate Manager (Free), a popular property management extension for Joomla, contains a critical unauthenticated SQL injection vulnerability tracked as CVE-2026-100752. The flaw exists in the component 'com_realestatemanager' (specifically in 'site/realestatemanager.php'), where the 'order_field' parameter is unsafely concatenated into an SQL ORDER BY clause. Because the application lacks allow-listing or proper input validation for this parameter, an unauthenticated attacker can inject arbitrary SQL commands. This can lead to full database enumeration, extraction of sensitive information such as user credentials, and potential administrative compromise of the underlying Joomla instance. A related reflected XSS vulnerability (CVE-2026-100753) was disclosed in the same security update train. Defenders must prioritize upgrading all OrdaSoft components to version 6.7.9 or later, as functional PoC code for this SQL injection is publicly available.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker performs discovery to identify Joomla sites running the 'com_realestatemanager' extension using Dorks or automated scanners.</li>
<li>Attacker verifies the target version by requesting 'site/realestatemanager.php' or checking the manifest file at '/administrator/components/com_realestatemanager/realestatemanager.xml'.</li>
<li>Attacker crafts a malicious HTTP GET or POST request targeting the 'showCategory' task in 'com_realestatemanager'.</li>
<li>Attacker injects a payload into the 'order_field' parameter (e.g., using UNION-based or error-based SQL injection techniques).</li>
<li>The Joomla server processes the malicious input and executes the injected SQL command against the database due to lack of input sanitization.</li>
<li>The backend database returns query results (e.g., database version, table contents, or user hashes) embedded in the HTTP response.</li>
<li>Attacker parses the response to exfiltrate database contents or further escalate privileges within the Joomla environment.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to read arbitrary data from the database, including site configuration, user lists, and password hashes. Given that the extension is used to manage real estate listings and customer data, this poses a significant risk to data privacy and site integrity. Organizations failing to patch are at high risk of full database exfiltration.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade OrdaSoft Real Estate Manager to version 6.7.9 or later immediately to patch CVE-2026-100752 and CVE-2026-100753.</li>
<li>Audit all OrdaSoft Joomla extensions for similar vulnerabilities, as other components in the same vendor suite were patched concurrently.</li>
<li>Deploy web application firewall (WAF) rules to inspect the 'order_field' parameter in requests to 'com_realestatemanager' for SQL injection patterns (e.g., SELECT, UNION, or comment sequences).</li>
<li>Use the provided Sigma rule to monitor for malicious injection attempts against the target component.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application-vulnerability</category><category>sqli</category><category>joomla</category></item></channel></rss>