Hi everyone, this isn't a bug in mojoPortal, but in .NET itself. This is an especially bad one for .NET 4.5, since the vulnerable feature (iriParsing) is enabled by default in .NET 4.5 and can't be switched off. This vulnerability can lead to remote code execution, so you should patch your servers as soon as possible, or notify your hosting provider to do so.
The patch is now available through Windows Update, as part of the regularly scheduled Windows 2nd Tuesday patches.
https://technet.microsoft.com/library/security/ms14-057