Unauthenticated Destructive CRUD in OrdaSoft Touch Slider for Joomla
CVE-2026-102781
What is CVE-2026-102781?
The OrdaSoft Touch Slider for Joomla contains a significant security vulnerability that allows unauthenticated users to exploit destructive Create, Read, Update, and Delete (CRUD) operations. This exposure arises from the modOsTouchSliderHelper::getAjax() function, which is improperly secured and directly handles all data management operations via Joomla’s core AJAX dispatcher without any necessary user authorizations or CSRF token checks. Attackers can leverage this flaw through two distinct methods: an unauthenticated GET request that enables the deletion of slider images using sequential IDs, and an unauthenticated multipart upload that allows the replacement of complete database tables with malicious content. The absence of protective parameters consequently poses a severe threat to website integrity.
Affected Version(s)
Touch Slider extension for Joomla 1.0.0-5.4.5
