Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3432 | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The application allows users to upload files with scripts in the filename parameter. As a result, a malicious user can upload a script file to the system. When users in the application use the "Diff or Compare" functionality, they are affected by a Stored Cross-Site Scripting vulnerability. This vulnerability is fixed in 4.2.9. |
Github GHSA |
GHSA-5jc6-h9w7-jm3p | Mobile Security Framework (MobSF) Stored Cross-Site Scripting Vulnerability in "Diff or Compare" Functionality |
Fri, 27 Jun 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opensecurity
Opensecurity mobile Security Framework |
|
| CPEs | cpe:2.3:a:opensecurity:mobile_security_framework:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Opensecurity
Opensecurity mobile Security Framework |
Tue, 03 Dec 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mobsf
Mobsf mobile Security Framework |
|
| CPEs | cpe:2.3:a:mobsf:mobile_security_framework:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mobsf
Mobsf mobile Security Framework |
|
| Metrics |
ssvc
|
Tue, 03 Dec 2024 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mobile Security Framework (MobSF) is a pen-testing, malware analysis and security assessment framework capable of performing static and dynamic analysis. The application allows users to upload files with scripts in the filename parameter. As a result, a malicious user can upload a script file to the system. When users in the application use the "Diff or Compare" functionality, they are affected by a Stored Cross-Site Scripting vulnerability. This vulnerability is fixed in 4.2.9. | |
| Title | Mobile Security Framework (MobSF) Stored Cross-Site Scripting Vulnerability in "Diff or Compare" Functionality | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-12-03T17:00:14.581Z
Reserved: 2024-11-25T23:14:36.384Z
Link: CVE-2024-53999
Updated: 2024-12-03T17:00:05.796Z
Status : Analyzed
Published: 2024-12-03T16:15:24.250
Modified: 2025-06-27T15:16:59.273
Link: CVE-2024-53999
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA