CVE-2026-102781
Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6
Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6 - modOsTouchSliderHelper::getAjax(), wired through Joomlaβs core com_ajax dispatcher, is the single handler behind every data-management operation this module exposes. No call to JFactory::getUser(), authorise(), or a CSRF token check exists anywhere in the handler. Two confirmed impact paths: an unauthenticated GET deletes any slider image by guessable sequential IDs, and an unauthenticated multipart upload with a zip file renames and replaces the entire #__os_touch_slider/#__os_touch_slider_text tables site-wide with attacker-supplied content, with no task parameter even required for the second path.
| CWE | CWE-284 |
| Vendor | ordasoft.com |
| Product | touch slider extension for joomla |
| Published | Oct 7, 2026 |
Get instant alerts for ordasoft.com touch slider extension for joomla
Be the first to know when new unknown vulnerabilities affecting ordasoft.com touch slider extension for joomla are published β delivered to Slack, Telegram or Discord.