CVE-2026-100753 Joomla Real Estate Manager 反射型跨站脚本漏洞
影响攻击者可利用恶意链接在受害者浏览器中执行任意脚本
Joomla 扩展 Real Estate Manager(免费版)的房产详情页“留下评论”表单存在反射型跨站脚本漏洞。该表单的 title 字段直接回显请求参数,未做任何转义或过滤,攻击者可构造恶意链接注入脚本。
影响范围
ordasoft.com 出品的 Real Estate Manager(Free)6.7.9 之前版本,具体受影响版本范围以官方公告为准。
漏洞详情
漏洞类型为反射型 XSS。房产详情页的评论表单在回显 title 查询参数时未进行 HTML 属性转义,攻击者只需在参数中插入双引号即可闭合原有属性,进而注入并执行任意 HTML/JavaScript 元素。
利用条件与风险
利用需诱导受害者点击特制链接,属于典型反射型 XSS,可窃取会话或冒充用户操作,实战风险中等。
修复建议
建议升级至 Real Estate Manager 6.7.9 或更高版本;临时缓解可对 title 参数进行严格过滤与 HTML 属性转义,或部署 WAF 拦截恶意请求。
Joomla Extension – ordasoft.com – Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9 – The public property-detail page’s “leave a review” form repopulates its title field directly from the request with no escaping and no filtering function of any kind, unlike the adjacent comment field on the same form, which at least receives partial tag-stripping. A " character in the title query parameter breaks out of the HTML attribute the value is placed in, allowing a following element to execute in the browser of anyone who loads the crafted link.