CNNVD-202602-2271 Information

CNNVD ID

CNNVD-202602-2271

CVE-2025-69770

  • CNNVD Published: 2026-02-13

Description (Chinese)

MojoPortal CMS是MojoPortal公司的一个内容管理系统。 MojoPortal CMS 2.9.0.1版本存在安全漏洞,该漏洞源于/DesignTools/SkinList.aspx端点存在zip slip漏洞,可能导致通过上传特制zip文件执行任意命令。

Description (English)

MojoPortal CMS is a content management system for Mojo Portal. MojoPortal CMS 2.9.0.1 has a security loophole, which stems from the zip slip gap at the /DesignTools/SkinList.aspx end point, which may lead to the execution of arbitrary orders by uploading a special zip file.

Vulnerability Type

其他

Affected Vendor

MojoPortal

Published

2026-02-13

Last Modified

2026-02-24

References

https://github.com/i7MEDIA/mojoportal/security https://github.com/kid-tnt/Mojo-check/blob/main/Zipslip%20in%20MojoPortal%20version%202.9.0.1.md https://www.mojoportal.com/mojoportal-2-9-1

Patch

https://www.mojoportal.com/download

Share on: