{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/real-estate-manager--6.7.8/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ordasoft:real_estate_manager:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-100752"},{"id":"CVE-2026-100753"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Real Estate Manager (\u003c= 6.7.8)"],"_cs_severities":["high"],"_cs_tags":["web-application-vulnerability","sqli","joomla"],"_cs_type":"advisory","_cs_vendors":["OrdaSoft"],"content_html":"\u003cp\u003eOrdaSoft Real Estate Manager (Free), a popular property management extension for Joomla, contains a critical unauthenticated SQL injection vulnerability tracked as CVE-2026-100752. The flaw exists in the component 'com_realestatemanager' (specifically in 'site/realestatemanager.php'), where the 'order_field' parameter is unsafely concatenated into an SQL ORDER BY clause. Because the application lacks allow-listing or proper input validation for this parameter, an unauthenticated attacker can inject arbitrary SQL commands. This can lead to full database enumeration, extraction of sensitive information such as user credentials, and potential administrative compromise of the underlying Joomla instance. A related reflected XSS vulnerability (CVE-2026-100753) was disclosed in the same security update train. Defenders must prioritize upgrading all OrdaSoft components to version 6.7.9 or later, as functional PoC code for this SQL injection is publicly available.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs discovery to identify Joomla sites running the 'com_realestatemanager' extension using Dorks or automated scanners.\u003c/li\u003e\n\u003cli\u003eAttacker verifies the target version by requesting 'site/realestatemanager.php' or checking the manifest file at '/administrator/components/com_realestatemanager/realestatemanager.xml'.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP GET or POST request targeting the 'showCategory' task in 'com_realestatemanager'.\u003c/li\u003e\n\u003cli\u003eAttacker injects a payload into the 'order_field' parameter (e.g., using UNION-based or error-based SQL injection techniques).\u003c/li\u003e\n\u003cli\u003eThe Joomla server processes the malicious input and executes the injected SQL command against the database due to lack of input sanitization.\u003c/li\u003e\n\u003cli\u003eThe backend database returns query results (e.g., database version, table contents, or user hashes) embedded in the HTTP response.\u003c/li\u003e\n\u003cli\u003eAttacker parses the response to exfiltrate database contents or further escalate privileges within the Joomla environment.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to read arbitrary data from the database, including site configuration, user lists, and password hashes. Given that the extension is used to manage real estate listings and customer data, this poses a significant risk to data privacy and site integrity. Organizations failing to patch are at high risk of full database exfiltration.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade OrdaSoft Real Estate Manager to version 6.7.9 or later immediately to patch CVE-2026-100752 and CVE-2026-100753.\u003c/li\u003e\n\u003cli\u003eAudit all OrdaSoft Joomla extensions for similar vulnerabilities, as other components in the same vendor suite were patched concurrently.\u003c/li\u003e\n\u003cli\u003eDeploy web application firewall (WAF) rules to inspect the 'order_field' parameter in requests to 'com_realestatemanager' for SQL injection patterns (e.g., SELECT, UNION, or comment sequences).\u003c/li\u003e\n\u003cli\u003eUse the provided Sigma rule to monitor for malicious injection attempts against the target component.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-29T00:27:47Z","date_published":"2026-09-29T00:27:47Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ordasoft-sqli/","summary":"OrdaSoft Real Estate Manager for Joomla versions 6.7.8 and earlier are vulnerable to unauthenticated SQL injection via the 'order_field' parameter, enabling unauthorized database access and data exfiltration.","title":"Unauthenticated SQL Injection in OrdaSoft Real Estate Manager","url":"https://feed.craftedsignal.io/briefs/2026-09-ordasoft-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Real Estate Manager (\u003c= 6.7.8)","version":"https://jsonfeed.org/version/1.1"}