- EPSS 0.12%
- Veröffentlicht 13.02.2026 00:00:00
- Zuletzt bearbeitet 13.02.2026 21:43:11
A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execute arbitrary commands via uploading a crafted zip file.
CVE-2025-28367
- EPSS 12.74%
- Veröffentlicht 21.04.2025 00:00:00
- Zuletzt bearbeitet 22.08.2025 13:05:04
mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this vulnerability to access the Web.Config file and obtain the MachineKey.
CVE-2023-44011
- EPSS 13.23%
- Veröffentlicht 02.10.2023 22:15:10
- Zuletzt bearbeitet 21.11.2024 08:25:06
An issue in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the layout.master skin file at the Skin management component.
CVE-2023-44012
- EPSS 15.2%
- Veröffentlicht 02.10.2023 22:15:10
- Zuletzt bearbeitet 21.11.2024 08:25:06
Cross Site Scripting vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the helpkey parameter in the Help.aspx component.
CVE-2023-44008
- EPSS 9.38%
- Veröffentlicht 02.10.2023 21:15:34
- Zuletzt bearbeitet 21.11.2024 08:25:05
File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the File Manager function.
CVE-2023-44009
- EPSS 9.38%
- Veröffentlicht 02.10.2023 21:15:34
- Zuletzt bearbeitet 21.11.2024 08:25:06
File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function.
CVE-2023-24689
- EPSS 0.25%
- Veröffentlicht 09.02.2023 20:15:12
- Zuletzt bearbeitet 24.03.2025 19:15:47
An issue in Mojoportal v2.7.0.0 and below allows an authenticated attacker to list all css files inside the root path of the webserver via manipulation of the "s" parameter in /DesignTools/ManageSkin.aspx
CVE-2023-24322
- EPSS 23.49%
- Veröffentlicht 09.02.2023 20:15:11
- Zuletzt bearbeitet 24.03.2025 19:15:41
A reflected cross-site scripting (XSS) vulnerability in the FileDialog.aspx component of mojoPortal v2.7.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the ed and tbi parameters.
CVE-2023-24323
- EPSS 0.19%
- Veröffentlicht 09.02.2023 20:15:11
- Zuletzt bearbeitet 24.03.2025 19:15:41
Mojoportal v2.7 was discovered to contain an authenticated XML external entity (XXE) injection vulnerability.
CVE-2023-24687
- EPSS 0.52%
- Veröffentlicht 09.02.2023 20:15:11
- Zuletzt bearbeitet 24.03.2025 19:15:46
Mojoportal v2.7.0.0 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the Company Info Settings component. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into t...