CVE-2026-102781: Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6

Published Oct 7, 2026
·
Updated

Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6 - modOsTouchSliderHelper::getAjax(), wired through Joomla’s core comajax dispatcher, is the single handler behind every data-management operation this module exposes. No call to JFactory::getUser(), authorise(), or a CSRF token check exists anywhere in the handler. Two confirmed impact paths: an unauthenticated GET deletes any slider image by guessable sequential IDs, and an unauthenticated multipart upload with a zip file renames and replaces the entire #ostouchslider/#ostouchslidertext tables site-wide with attacker-supplied content, with no task parameter even required for the second path.

Affected Software

1 affected component
ordasoft Touch Slider<5.4.6

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OrdaSoft Touch Slider to a version that resolves this vulnerability.

    Fixed in 5.4.6

Event History

Oct 7, 2026
CVE Published
via MITRE·08:02 AM
Data Sourced
via MITRE·08:02 AM
DescriptionWeakness
Data Sourced
via NVD·09:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any remote, unauthenticated attacker can exploit the exposed AJAX handler. No account, permission, user interaction, or CSRF token is required.

2

What operations can an attacker perform?

An attacker can delete slider images through unauthenticated GET requests when image IDs can be guessed. They can also submit a multipart upload containing a ZIP file to replace the site-wide os_touch_slider and os_touch_slider_text database tables with attacker-controlled content.

3

Are installations affected without special configuration?

The vulnerable handler is wired through Joomla’s core com_ajax dispatcher and handles every data-management operation exposed by the module. The described upload path does not require a task parameter.

4

How can administrators determine whether they are affected?

Installations using OrdaSoft Touch Slider versions earlier than 5.4.6 are affected. Signs of exploitation may include missing slider images or unexpected replacement of slider and slider-text data.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203