Impact
This vulnerability allows an unauthenticated attacker to inject arbitrary SQL through the order_field request parameter used to build ORDER BY clauses of several property‑listing queries. Because the parameter is embedded directly into unquoted SQL without any validation or whitelisting, the attacker can modify the query logic to leak or alter database contents, leading to unauthorized data exposure or manipulation.
Affected Systems
Ordasoft.com’s Real Estate Manager (Free) extension for Joomla, any installation running a version older than 6.7.9. No specific patch set is listed, so all affected releases up to 6.7.8 or lower are vulnerable.
Risk and Exploitability
With a CVSS score of 9.3, this flaw represents a high‑severity exploitation risk. The EPSS score is currently unavailable, so the exact exploitation probability is unknown, and it is not listed in the CISA KEV catalog. The likely attack vector is a standard web attack, where an attacker submits a crafted order_field value through a publicly reachable URL; based on the description, it is inferred that no authentication is required to reach the vulnerable code path.
OpenCVE Enrichment