RULE(RULE ID:338943)

Rule General Information
Release Date: 2025-05-20
Rule Name: mojoPortal Directory Traversal Vulnerability (CVE-2025-28367)
Severity:
CVE ID:
Rule Protection Details
Description: mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this vulnerability to access the Web.Config file and obtain the MachineKey.
Impact: An attacker can abtain sensitive information of the target victim, and do malicious actions to gain profits using the information.
Affected OS: Windows, Linux, Others
Reference: https://github.com/i7MEDIA/mojoportal
https://www.0xlanks.me/blog/cve-2025-28367-advisory/
Solutions
Please contact the software vendor to update the software patch.