CVE-2025-28367

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 21, 2025
Updated: Apr 23, 2025
CWE ID 284

Summary

CVE-2025-28367 is a directory traversal vulnerability affecting mojoPortal versions below 2.9.0.1. The BetterImageGallery API Controller's ImageHandler action is the culprit, allowing an attacker to manipulate file paths and access sensitive files, including the Web.Config file. This exposure of the Web.Config file grants an attacker the ability to obtain the MachineKey, potentially leading to further unauthorized actions.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share