Description
Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9 - The public property-detail page’s “leave a review” form repopulates its title field directly from the request with no escaping and no filtering function of any kind, unlike the adjacent comment field on the same form, which at least receives partial tag-stripping. A " character in the title query parameter breaks out of the HTML attribute the value is placed in, allowing a following <script> element to execute in the browser of anyone who loads the crafted link.
Published: 2026-09-28
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Cross‑site scripting that allows arbitrary client‑side script execution via the property‑detail review form.
Action: Apply Patch
AI Analysis

Impact

The Real Estate Manager (Free) Joomla extension exposes a reflected XSS vulnerability on the property‑detail page’s leave‑a‑review form. The title field is populated directly from the request without escaping or filtering, enabling an attacker to insert a quote character that terminates the attribute and embed a <script> element. Victim browsers executing the crafted URL would run the attacker’s script, potentially facilitating phishing, cookie theft, or malicious redirects. No server‑side data compromise occurs, but the flaw can undermine user trust and serve as a foothold for further social‑engineering attacks.

Affected Systems

The vulnerability exists in all installations of ordasoft.com’s Real Estate Manager (Free) extension for Joomla with versions older than 6.7.9. No additional product or platform information is provided beyond the vendor and extension name.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity; the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by crafting a URL that includes an unescaped title parameter and persuading or tricking users into visiting it. Because the impact is limited to the client side and requires the target to load the injected link, the exploitability is moderate and the compromise is confined to user browsers rather than the server itself.

Generated by OpenCVE AI on September 28, 2026 at 20:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Real Estate Manager (Free) extension to version 6.7.9 or later to eliminate the unchecked title field.
  • Modify the review form processing to escape all user‑supplied data before rendering it in the title attribute, ensuring that special characters are not interpreted as markup.
  • Configure a stringent Content‑Security‑Policy header to restrict the execution of inline scripts and mitigate any remaining XSS vectors that may escape the immediate fix.

Generated by OpenCVE AI on September 28, 2026 at 20:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.ordasoft.com/ cve-icon cve-icon
History

Mon, 28 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Description Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9 - The public property-detail page’s “leave a review” form repopulates its title field directly from the request with no escaping and no filtering function of any kind, unlike the adjacent comment field on the same form, which at least receives partial tag-stripping. A " character in the title query parameter breaks out of the HTML attribute the value is placed in, allowing a following <script> element to execute in the browser of anyone who loads the crafted link.
Title Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-09-28T18:41:14.007Z

Reserved: 2026-09-26T14:38:32.304Z

Link: CVE-2026-100753

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T19:16:46.220

Modified: 2026-09-28T19:16:46.220

Link: CVE-2026-100753

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T20:30:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')