Unauthenticated SQL Injection Vulnerability in Real Estate Manager by Ordasoft
CVE-2026-100752

9.3CRITICAL

Key Information:

Vendor
CVE Published:
28 September 2026

What is CVE-2026-100752?

The Real Estate Manager plugin from Ordasoft contains a significant SQL injection vulnerability, allowing unauthenticated users to manipulate SQL queries. This vulnerability arises from the way the ORDER BY clause is constructed using the request-controlled order_field parameter. Without proper sanitization and validation, attackers can inject malicious SQL code, potentially leading to data exposure or manipulation. It's crucial to update to versions 6.7.9 or above to mitigate this risk.

Affected Version(s)

Real Estate Manager (Free) extension for Joomla 1.0.0-6.7.8

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ala Arfaoui
.