CVE-2026-102781: CWE-284 Improper Access Control in ordasoft.com Touch Slider extension for Joomla
Description
Joomla Extension - ordasoft.com - Unauthenticated Destructive CRUD in OrdaSoft Touch Slider < 5.4.6 - modOsTouchSliderHelper::getAjax(), wired through Joomla’s core com_ajax dispatcher, is the single handler behind every data-management operation this module exposes. No call to JFactory::getUser(), authorise(), or a CSRF token check exists anywhere in the handler. Two confirmed impact paths: an unauthenticated GET deletes any slider image by guessable sequential IDs, and an unauthenticated multipart upload with a zip file renames and replaces the entire #__os_touch_slider/#__os_touch_slider_text tables site-wide with attacker-supplied content, with no task parameter even required for the second path.
CVSS v4.0
Score 6.9medium
Affected software
ordasoft.com
Touch Slider extension for Joomla
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The OrdaSoft Touch Slider extension for Joomla versions 1.0.0 to 5.4.5 contains an improper access control vulnerability (CWE-284) in the modOsTouchSliderHelper::getAjax() function. This function is the sole handler for all data management operations exposed by the module and is accessible through Joomla's core com_ajax dispatcher. It does not perform any user authentication, authorization, or CSRF token validation. As a result, unauthenticated attackers can delete slider images by guessing sequential IDs via GET requests or upload a ZIP file that renames and replaces the entire #__os_touch_slider and #__os_touch_slider_text database tables with attacker-controlled content, without needing to specify a task parameter.
Potential Impact
An unauthenticated attacker can delete any slider image by guessing its ID, causing denial of service or content disruption. More severely, the attacker can replace entire database tables related to the slider with malicious content, potentially compromising site integrity and availability. This can lead to site defacement, data loss, or further exploitation depending on the attacker's payload. No privileges or user interaction are required to exploit these flaws.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the com_ajax endpoint if possible or disable the OrdaSoft Touch Slider extension. Monitor for updates from ordasoft.com and Joomla regarding official patches or mitigations. Avoid exposing the vulnerable module to unauthenticated users.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Joomla
- Date Reserved
- 2026-09-29T16:46:15.044Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac607832cdf04f6562f2fe0
Added to database: 10/07/2026, 08:49:07 UTC
Last enriched: 10/07/2026, 09:03:48 UTC
Last updated: 10/08/2026, 05:18:53 UTC
Views: 16
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.