Unauthenticated Destructive CRUD in OrdaSoft Touch Slider for Joomla
CVE-2026-102781

6.9MEDIUM

Key Information:

Vendor
CVE Published:
7 October 2026

What is CVE-2026-102781?

The OrdaSoft Touch Slider for Joomla contains a significant security vulnerability that allows unauthenticated users to exploit destructive Create, Read, Update, and Delete (CRUD) operations. This exposure arises from the modOsTouchSliderHelper::getAjax() function, which is improperly secured and directly handles all data management operations via Joomla’s core AJAX dispatcher without any necessary user authorizations or CSRF token checks. Attackers can leverage this flaw through two distinct methods: an unauthenticated GET request that enables the deletion of slider images using sequential IDs, and an unauthenticated multipart upload that allows the replacement of complete database tables with malicious content. The absence of protective parameters consequently poses a severe threat to website integrity.

Affected Version(s)

Touch Slider extension for Joomla 1.0.0-5.4.5

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.