PT-2024-5612 · Unknown · Mobile Security Framework

Marcin Węgłowski

·

Published

2024-07-31

·

Updated

2024-08-15

·

CVE-2024-41955

CVSS v4.0

6.8

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:A/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Mobile Security Framework (MobSF) versions prior to 4.0.5
Description The issue is related to an open redirect vulnerability in the authentication view of Mobile Security Framework (MobSF), a security research platform for mobile applications. This vulnerability can be exploited by an attacker to conduct phishing attacks using a specially crafted malicious link. Users who are not using authentication are not impacted.
Recommendations Update to MobSF version 4.0.5 to resolve the issue. As a temporary workaround, consider disabling authentication until a patch is available.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

BDU:2024-06304
CVE-2024-41955
GHSA-8M9J-2F32-2VX4

Affected Products

Mobile Security Framework