CVE-2025-28367: Directory Traversal in mojoPortal Image Handler API

ISGroup Cybersecurity

A medium-severity vulnerability has been identified in mojoPortal, an open-source CMS platform widely used by educational institutions, government websites, and small businesses. This flaw allows unauthenticated attackers to access sensitive files via a legacy image management API. The goal of this disclosure is to highlight the risks associated with insecure file access patterns and emphasize the importance of user input validation, particularly for legacy code still exposed online.

ProductmojoPortal
Date2025-04-22 12:26:11
Information
  • Trending

Technical Summary

The vulnerability exists in mojoPortal versions ≤ 2.9.0.1, specifically in the /api/BetterImageGallery/imagehandler endpoint. This handler does not properly sanitize the path parameter, allowing for directory traversal attacks that expose internal configuration files.

Key technical points:

  • Unauthenticated file access: The handler accepts file paths from user input without restricting traversal beyond the intended image directory.
  • Web.Config access: An attacker can request ../../../Web.Config, obtaining sensitive application secrets such as encryption keys and database credentials.
  • Legacy endpoint: The vulnerable endpoint is part of an old image management module, which may no longer be actively maintained in many installations.

Recommendations

Patch (awaiting official release)

  • Monitor the mojoPortal GitHub repository for any official patches or release notes related to this issue.
  • Temporarily remove or restrict access to the BetterImageGallery API if it is not in active use.

Temporary mitigation

  • Implement middleware or filters in the reverse proxy to block ../ patterns in URLs.
  • Restrict access to .config files at the web server level (IIS or Apache).

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert