Executive brief
A security vulnerability exists in the Ultimate Property Listing extension for Joomla, which is used to manage real estate listings on websites. An unauthorized attacker can exploit this flaw to access the website's underlying database without needing a password. This could lead to the theft of sensitive information, including user data and site configuration details.
Technical details
An SQL injection vulnerability exists in Joomla Ultimate Property Listing version 1.0.2 due to improper neutralization of special elements in the 'sf_selectuser_id' parameter. An unauthenticated remote attacker can exploit this by sending specially crafted GET requests to index.php with 'option=com_upl' and 'view=propertylisting' parameters. Successful exploitation allows the attacker to execute arbitrary SQL commands, enabling the extraction of sensitive database information such as table names, column structures, and stored data. The vulnerability is classified as CWE-89.
Affected products
- Faboba Ultimate Property Listing 1.0.2
Timeline
- 2026-06-19: disclosed: CVE published/updated via VulnCheck and NVD