All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2025-69770
CRITICALpublished 2026-02-13 18:16 UTC · 6 months ago · modified 2026-06-17 10:00 UTC
10.0
CVSS / 10
// description
A zip slip vulnerability in the /DesignTools/SkinList.aspx endpoint of MojoPortal CMS v2.9.0.1 allows attackers to execute arbitrary commands via uploading a crafted zip file.
// weaknesses (CWE)
- CWE-22