PT-2026-8017 · Unknown · Mojoportal Cms

CVE-2025-69770

·

Publicado

2026-02-13

·

Atualizado

2026-02-18

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MojoPortal CMS version 2.9.0.1
Description A zip slip vulnerability exists in the /DesignTools/SkinList.aspx API endpoint of the software. This allows attackers to execute arbitrary commands by uploading a specially crafted zip file. The zip file is processed without sufficient security checks, potentially leading to unintended file extraction and code execution. The vulnerable parameter is the uploaded zip file.
Recommendations Apply updates to address the zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint.

Correção

RCE

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-69770

Produtos afetados

Mojoportal Cms