Real Estate Manager SQLi lets attackers read DB (CVE-2026-100752) [PoC]
CVE-2026-100752
CVE-2026-100752: unauthenticated SQL injection in Joomla Real Estate Manager < 6.7.9 lets attackers read or alter your database. Update to 6.7.9 now.
Exploitation confirmed - public proof-of-concept - CVE-2026-100752 is a critical unauthenticated SQL injection in the Joomla extension Real Estate Manager (Free) before version 6.7.9 that lets any remote attacker read, alter, or delete data in the site’s database without logging in. Update to 6.7.9 immediately.
Overview
Real Estate Manager is a Joomla component from ordasoft.com used to publish property listings. Three separate frontend listing queries - category browsing, search results, and the full property listing - build their SQL ORDER BY clause from a request-controlled order_field parameter. The value is concatenated straight into the SQL statement inside an unquoted clause, with no allow-list of valid column names and no type cast. Because the three queries are reachable without authentication, anyone who can reach the site can supply a crafted order_field value and inject their own SQL.
The vulnerability is tracked as CVE-2026-100752 and carries a CVSS score of 9.3. Exploitation is confirmed and a public proof-of-concept exists, though CISA has not added this CVE to the Known Exploited Vulnerabilities catalog, so active in-the-wild attacks are not confirmed at this time. Treat the public PoC as a strong signal that opportunistic scanning is likely.
Impact
An unauthenticated attacker can inject SQL through the listing pages, subject to the database privileges of the Joomla database user. That typically means reading arbitrary tables - including Joomla administrator password hashes, session data, and any customer or listing data stored in the same database - and in many configurations modifying or deleting rows. On shared hosting where the Joomla database user holds broad privileges, the same injection can be used to write files or pivot toward the underlying host. Because no authentication or user interaction is required, automated exploitation at scale is trivial once the PoC circulates.
Any site running Real Estate Manager (Free) below 6.7.9 is affected. Sites that expose listing or search pages to anonymous visitors are the most exposed, which is the default configuration for a public real estate site.
Remediation
The vendor fix is available: upgrade Real Estate Manager (Free) to 6.7.9 or later. This is the only complete remediation, since the flaw is in the component code itself.
Until you can upgrade:
- Disable or unpublish the Real Estate Manager component if listings are not business-critical.
- Restrict access to the affected frontend pages using a Web Application Firewall rule that blocks suspicious
order_fieldvalues, especially those containing quotes, parentheses, commas, or SQL keywords. - Review database user privileges and confirm the Joomla database account cannot write files or access unrelated schemas.
- Rotate Joomla administrator credentials and any secrets stored in the database, and review logs for unusual
order_fieldparameters in listing and search requests.
If you suspect compromise, data breach reports are available at breach reports and ongoing coverage at security news.
Security Insight
This case follows a recurring pattern in Joomla extension security: a single unvalidated parameter feeding three separate query paths, which multiplies the attack surface from one flaw. ORDER BY injection is especially easy to overlook because the clause sits at the end of the statement and developers often assume column names are harmless. That assumption fails the moment user input reaches the clause unquoted. The real lesson is architectural: extensions that build SQL fragments from request data need a strict allow-list of column names, not input filtering, and that allow-list should be enforced in one shared query builder rather than copied across three call sites.
Further Reading
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Public PoC References
Unverified third-party code
These repositories are publicly listed on GitHub and have not been audited by Yazoul Security. They may contain malware, backdoors, destructive payloads, or operational security risks (telemetry, exfiltration). Treat them as hostile binaries. Inspect source before execution. Run only in isolated, disposable lab environments (offline VM, no credentials, no production data).
Authorized use only. This information is provided for defensive research, detection engineering, and patch validation. Using exploit code against systems you do not own or do not have explicit written permission to test is illegal in most jurisdictions and violates Yazoul's terms of use.
| Repository | Stars |
|---|---|
| murrez/CVE-2026-100752 CVE-2026-100752 PoC: OrdaSoft Joomla Real Estate Manager (Free) <=6.7.8 unauth SQLi via order_field ORDER BY (com_realestatemanager). Colored check + mass exploit, version fingerprint, PoCbit https:// | ★ 0 |
Showing 1 of 1 known references. Source: nomi-sec/PoC-in-GitHub.
Related Advisories
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Vehicle Manager (Free) < 6.5.8 - site/vehiclemanager.php reads the order_field and order_direction sort parameters at three separate ...
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Book Library (Free) < 6.4.6 - site/booklibrary.php’s books() function reads the field and direction request parameters and passes eac...
Joomla Extension - joomlaboat.com - Unauthenticated SQL injection in YouTube Gallery extension < 5.7.3 - An SQL injection vulnerability in video search functionality and sorting allowed attackers to i...
YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated visitor of a defau...