Medium severity6.5NVD Advisory· Published Apr 21, 2025· Updated Jun 17, 2026
CVE-2025-28367
CVE-2025-28367
Description
mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this vulnerability to access the Web.Config file and obtain the MachineKey.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:mojoportal:mojoportal:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:mojoportal:mojoportal:*:*:*:*:*:*:*:*range: <2.9.1.0
- (no CPE)range: <=2.9.0.1
- mojoPortal/mojoPortaldescription
Patches
Vulnerability mechanics
References
1- www.0xlanks.me/blog/cve-2025-28367-advisory/nvdExploitPatchThird Party Advisory
News mentions
0No linked articles in our index yet.