Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.ordasoft.com/ |
|
Wed, 07 Oct 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6 - modOsTouchSliderHelper::getAjax(), wired through Joomla’s core com_ajax dispatcher, is the single handler behind every data-management operation this module exposes. No call to JFactory::getUser(), authorise(), or a CSRF token check exists anywhere in the handler. Two confirmed impact paths: an unauthenticated GET deletes any slider image by guessable sequential IDs, and an unauthenticated multipart upload with a zip file renames and replaces the entire #__os_touch_slider/#__os_touch_slider_text tables site-wide with attacker-supplied content, with no task parameter even required for the second path. | |
| Title | Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6 | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Joomla
Published:
Updated: 2026-10-07T15:35:54.867Z
Reserved: 2026-09-29T16:46:15.044Z
Link: CVE-2026-102781
No data.
Status : Awaiting Analysis
Published: 2026-10-07T09:17:04.397
Modified: 2026-10-07T14:46:20.007
Link: CVE-2026-102781
No data.
OpenCVE Enrichment
Updated: 2026-10-07T09:30:14Z
-
CWE-284
Improper Access Control