mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal...
        
  Moderate severity
        
          Unreviewed
      
        Published
          Apr 21, 2025 
          to the GitHub Advisory Database
          •
          Updated Apr 21, 2025 
      
  
Description
        Published by the National Vulnerability Database
      Apr 21, 2025 
    
  
        Published to the GitHub Advisory Database
      Apr 21, 2025 
    
  
        Last updated
      Apr 21, 2025 
    
  
mojoPortal <=2.9.0.1 is vulnerable to Directory Traversal via BetterImageGallery API Controller - ImageHandler Action. An attacker can exploit this vulnerability to access the Web.Config file and obtain the MachineKey.
References