CVE-2025-28367 | mojoPortal up to 2.9.0.1 BetterImageGallery API Controller Web.Config ImageHandler path traversal
A vulnerability, which was classified as problematic, was found in mojoPortal up to 2.9.0.1. This affects the function ImageHandler of the file Web.Config of the component BetterImageGallery API Controller. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2025-28367. Access to the local network is required for this attack to succeed. There is no exploit available.