{"id":"CVE-2026-102781","title":"Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6 - modOsTouchSliderHelper::getAjax(), wired through Joomla’s core com_ajax dispatcher, is the single handler behind every data-management …","summary":"Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6 - modOsTouchSliderHelper::getAjax(), wired through Joomla’s core com_ajax dispatcher, is the single handler behind every data-management …","severity":"medium","cvss":6.9,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N","cwe":["CWE-284"],"vendor":"ordasoft.com","product":"mod_os_touchslider","affected":["mod_os_touchslider 1.0.0-5.4.5"],"published":"2026-10-07","updated":"2026-10-07","sourceUpdated":"2026-10-07T09:17:04.397","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-102781","references":[{"url":"https://www.ordasoft.com/","label":"security@joomla.org"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-10-07T09:22:30.525Z","slug":"CVE-2026-102781","body":"## Overview\n\nJoomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6 - modOsTouchSliderHelper::getAjax(), wired through Joomla’s core com_ajax dispatcher, is the single handler behind every data-management operation this module exposes. No call to JFactory::getUser(), authorise(), or a CSRF token check exists anywhere in the handler. Two confirmed impact paths: an unauthenticated GET deletes any slider image by guessable sequential IDs, and an unauthenticated multipart upload with a zip file renames and replaces the entire #__os_touch_slider/#__os_touch_slider_text tables site-wide with attacker-supplied content, with no task parameter even required for the second path.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":38,"depthScoreParts":{"impact":38,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}