CVE-2026-100752 is an unauthenticated SQL injection vulnerability in OrdaSoft Real Estate Manager (Free) for Joomla versions earlier than 6.7.9. Frontend category-browsing, search-result, and full property-listing queries construct SQL ORDER BY clauses from the request-controlled order_field parameter. The parameter is concatenated directly into an unquoted SQL clause without an allow-list of permitted sortable column names or type casting, allowing attacker-controlled SQL to be incorporated into affected queries.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This six-file repository is a standalone Python 3 operational PoC for CVE-2026-100752 affecting OrdaSoft Real Estate Manager (Free) for Joomla through version 6.7.8. Its sole code file, poc.py, uses requests and urllib3 to fingerprint com_realestatemanager, optionally retrieve exposed administrator manifests for version detection, scrape category/menu identifiers, and test several public Joomla task routes. It targets an unvalidated order_field value used in an SQL ORDER BY clause through GET and POST requests, with a retained legacy order_direction POST fallback. Check mode uses SQL-error/boolean-style evidence and optional aggressive probing; exploit mode sends an error-based extraction payload and parses MySQL-family errors plus tilde-delimited leaked output. It supports individual URLs and concurrent target lists, proxying, configurable timeout/thread count, forced injection-vector selection, JSON/JSONL reporting, and hit/exploitation lists. README.md provides usage, asset-discovery queries, mitigation guidance, and a stated fixed version of 6.7.9; requirements.txt lists requests and urllib3, while targets.example.txt contains only non-routable example target URLs.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An unauthenticated SQL injection vulnerability in OrdaSoft Real Estate Manager (Free) versions before 6.7.9 for Joomla. The request-controlled order_field parameter is directly concatenated into unquoted ORDER BY clauses in multiple frontend property-listing queries without allow-list validation or type casting.
An unauthenticated SQL injection vulnerability in OrdaSoft Real Estate Manager (Free) for Joomla versions earlier than 6.7.9. A remote attacker can manipulate the request-controlled order_field parameter used to construct SQL ORDER BY clauses in frontend property-listing queries, potentially compromising database confidentiality, integrity, and availability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.