Impact
The vulnerability arises from the modOsTouchSliderHelper::getAjax handler, which is used for all data‑management operations in the Touch Slider extension for Joomla. The handler performs no user authentication, no permission checks, nor does it verify a CSRF token. Consequently an attacker can execute destructive operations without logging in – either deleting slider images via a guessed sequential ID or overwriting the entire slider tables by uploading a crafted zip file. The impact is loss or complete replacement of website slider content, potentially causing site downtime and loss of user trust.
Affected Systems
Joomla websites that have the Touch Slider extension installed from ordasoft.com with a version earlier than 5.4.6 are affected. No further version granularity is provided beyond the stated maximum vulnerable version. All Joomla sites running that extension without recent upgrades are at risk.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. Because the attack does not require authentication, any web client can exploit this flaw, making the exploitation likelihood high in the absence of mitigations. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the lack of checks coupled with the ease of interaction via the com_ajax dispatcher suggests that attackers could routinely exploit it. An attacker can readily discover the endpoint, guess IDs or upload payloads, and alter or delete content without detection.
OpenCVE Enrichment