Vulnerability Information for CVE-2023-44009 Basic Information Date: 29/09/2023 Affected Version: mojoPortal 2.7.0.0 Vendor Homepage: https://www.mojoptoral.com/ Exploit Author: Hoang of VietSunshine Cyber Security Services Description File Upload vulnerability in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via the Skin Management function. Attack Vectors Access Design Tools - Skin Management: Upload a compressed skin that contains malicious code at the file Raw Request Example `` http://[site]/?skin=[skin_name]` to execute malicious code