Joomla 扩展 - ordasoft.com - OrdaSoft Touch Slider < 5.4.6 中存在未授权的破坏性 CRUD 漏洞 - modOsTouchSliderHelper::getAjax() 通过 Joomla 核心 com_ajax 分发器连接,是该模块暴露的所有数据管理操作背后的唯一处理程序。在该处理程序中,没有任何调用 JFactory::getUser()、authorise() 或 CSRF 令牌检查的代码。存在两个已确认的影响路径:一个未授权的 GET 请求可以通过猜测顺
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| ordasoft.com | Touch Slider extension for Joomla | 1.0.0-5.4.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet