Impact
The Real Estate Manager (Free) Joomla extension exposes a reflected XSS vulnerability on the property‑detail page’s leave‑a‑review form. The title field is populated directly from the request without escaping or filtering, enabling an attacker to insert a quote character that terminates the attribute and embed a <script> element. Victim browsers executing the crafted URL would run the attacker’s script, potentially facilitating phishing, cookie theft, or malicious redirects. No server‑side data compromise occurs, but the flaw can undermine user trust and serve as a foothold for further social‑engineering attacks.
Affected Systems
The vulnerability exists in all installations of ordasoft.com’s Real Estate Manager (Free) extension for Joomla with versions older than 6.7.9. No additional product or platform information is provided beyond the vendor and extension name.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity; the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by crafting a URL that includes an unescaped title parameter and persuading or tricking users into visiting it. Because the impact is limited to the client side and requires the target to load the injected link, the exploitability is moderate and the compromise is confined to user browsers rather than the server itself.
OpenCVE Enrichment