CyberRota Analysis
AI-GeneratedThe Joomla Extension from ordasoft.com is vulnerable to an unauthenticated SQL injection in the Real Estate Manager version prior to 6.7.9, allowing attackers to manipulate the ORDER BY clause in property-listing queries through the request-controlled order_field parameter. This critical vulnerability, with a CVSS score of 9.3, can lead to unauthorized data access and potential database compromise. Joomla administrators and developers using this extension should prioritize immediate remediation to mitigate risks associated with this exploit.
Original NVD Description
Joomla Extension - ordasoft.com - Unauthenticated SQL Injection in Real Estate Manager (Free) < 6.7.9 - site/realestatemanager.php builds the ORDER BY clause of three separate frontend property-listing queries (category browsing, search results, and the full property listing) from a request-controlled order_field parameter, concatenated directly into an unquoted SQL clause with no allow-list of real column names and no cast.