Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Dat Hoang

Researcher fromVietSunshine Cyber Security Services
#17560of 53,624
15.3Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2022-25227
6.5
2022-10-03
Unknown · Mojoportal · CVE-2022-40123
**Name of the Vulnerable Software and Affected Versions** mojoPortal version 2.7 **Description** The issue allows authenticated attackers to read arbitrary files in the system due to a path traversal vulnerability. This vulnerability can be exploited via the `f` parameter at the "/DesignTools/CssEditor.aspx" API endpoint. **Recommendations** For mojoPortal version 2.7, consider restricting access to the "/DesignTools/CssEditor.aspx" API endpoint to minimize the risk of exploitation. Avoid using the `f` parameter in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2022-25354
8.8
2022-09-30
Unknown · Mojoportal · CVE-2022-40341
**Name of the Vulnerable Software and Affected Versions** mojoPortal version 2.7 **Description** The issue allows attackers to execute arbitrary code via a crafted PNG file, exploiting an arbitrary file upload vulnerability. **Recommendations** For mojoPortal version 2.7, consider disabling the file upload feature until a patch is available to prevent exploitation of the arbitrary file upload vulnerability.