Description
Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6 - modOsTouchSliderHelper::getAjax(), wired through Joomla’s core com_ajax dispatcher, is the single handler behind every data-management operation this module exposes. No call to JFactory::getUser(), authorise(), or a CSRF token check exists anywhere in the handler. Two confirmed impact paths: an unauthenticated GET deletes any slider image by guessable sequential IDs, and an unauthenticated multipart upload with a zip file renames and replaces the entire #__os_touch_slider/#__os_touch_slider_text tables site-wide with attacker-supplied content, with no task parameter even required for the second path.
Published: 2026-10-07
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: Unauthenticated destructive CRUD compromising site content
Action: Upgrade Extension
AI Analysis

Impact

The vulnerability arises from the modOsTouchSliderHelper::getAjax handler, which is used for all data‑management operations in the Touch Slider extension for Joomla. The handler performs no user authentication, no permission checks, nor does it verify a CSRF token. Consequently an attacker can execute destructive operations without logging in – either deleting slider images via a guessed sequential ID or overwriting the entire slider tables by uploading a crafted zip file. The impact is loss or complete replacement of website slider content, potentially causing site downtime and loss of user trust.

Affected Systems

Joomla websites that have the Touch Slider extension installed from ordasoft.com with a version earlier than 5.4.6 are affected. No further version granularity is provided beyond the stated maximum vulnerable version. All Joomla sites running that extension without recent upgrades are at risk.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. Because the attack does not require authentication, any web client can exploit this flaw, making the exploitation likelihood high in the absence of mitigations. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the lack of checks coupled with the ease of interaction via the com_ajax dispatcher suggests that attackers could routinely exploit it. An attacker can readily discover the endpoint, guess IDs or upload payloads, and alter or delete content without detection.

Generated by OpenCVE AI on October 7, 2026 at 09:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Touch Slider to version 5.4.6 or later to eliminate the unauthenticated handler flaw.
  • If an upgrade is not immediately possible, restrict access to the extension’s com_ajax endpoint via web‑application firewall rules or .htaccess restrictions, limiting requests to trusted IP ranges and removing default GET endpoints that trigger destructive actions.
  • Enable Joomla’s network security features (e.g., CSRF token enforcement and user authentication) and audit the module’s code to ensure that all data‑management requests undergo proper authorisation checks before execution.

Generated by OpenCVE AI on October 7, 2026 at 09:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://www.ordasoft.com/ cve-icon cve-icon
History

Wed, 07 Oct 2026 08:45:00 +0000

Type Values Removed Values Added
Description Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6 - modOsTouchSliderHelper::getAjax(), wired through Joomla’s core com_ajax dispatcher, is the single handler behind every data-management operation this module exposes. No call to JFactory::getUser(), authorise(), or a CSRF token check exists anywhere in the handler. Two confirmed impact paths: an unauthenticated GET deletes any slider image by guessable sequential IDs, and an unauthenticated multipart upload with a zip file renames and replaces the entire #__os_touch_slider/#__os_touch_slider_text tables site-wide with attacker-supplied content, with no task parameter even required for the second path.
Title Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6
Weaknesses CWE-284
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-10-07T08:02:35.849Z

Reserved: 2026-09-29T16:46:15.044Z

Link: CVE-2026-102781

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-07T09:17:04.397

Modified: 2026-10-07T09:17:04.397

Link: CVE-2026-102781

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T09:30:14Z

Weaknesses