CVE-2024-53999

Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The application allows users to upload files with scripts in the filename parameter. As a result, a malicious user can upload a script file to the system. When users in the application use the "Diff or Compare" functionality, they are affected by a Stored Cross-Site Scripting vulnerability. This vulnerability is fixed in 4.2.9.
Configurations

Configuration 1 (hide)

cpe:2.3:a:opensecurity:mobile_security_framework:*:*:*:*:*:*:*:*

History

27 Jun 2025, 15:16

Type Values Removed Values Added
First Time Opensecurity
Opensecurity mobile Security Framework
CPE cpe:2.3:a:opensecurity:mobile_security_framework:*:*:*:*:*:*:*:*
Summary
  • (es) Mobile Security Framework (MobSF) es un framework de evaluación de seguridad, análisis de malware y pruebas de penetración capaz de realizar análisis estáticos y dinámicos. La aplicación permite a los usuarios cargar archivos con scripts en el parámetro filename. Como resultado, un usuario malintencionado puede cargar un archivo de script al sistema. Cuando los usuarios de la aplicación utilizan la función "Diff or Compare", se ven afectados por una vulnerabilidad de Cross-Site Scripting almacenado. Esta vulnerabilidad se solucionó en la versión 4.2.9.
References () https://github.com/MobSF/Mobile-Security-Framework-MobSF/commit/27d165872847f5ae7417caf09f37edeeba741e1e - () https://github.com/MobSF/Mobile-Security-Framework-MobSF/commit/27d165872847f5ae7417caf09f37edeeba741e1e - Patch
References () https://github.com/MobSF/Mobile-Security-Framework-MobSF/security/advisories/GHSA-5jc6-h9w7-jm3p - () https://github.com/MobSF/Mobile-Security-Framework-MobSF/security/advisories/GHSA-5jc6-h9w7-jm3p - Exploit, Vendor Advisory

03 Dec 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-03 16:15

Updated : 2025-06-27 15:16


NVD link : CVE-2024-53999

Mitre link : CVE-2024-53999

CVE.ORG link : CVE-2024-53999


JSON object : View

Products Affected

opensecurity

  • mobile_security_framework
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')