Описание
Mobile Security Framework (MobSF) v0.9.2 and below was discovered to contain a local file inclusion (LFI) vulnerability in the StaticAnalyzer/views.py script. This vulnerability allows attackers to read arbitrary files via a crafted HTTP request.
Ссылки
- PatchThird Party Advisory
- ExploitThird Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.9.2 (включая)
cpe:2.3:a:opensecurity:mobile_security_framework:*:*:*:*:*:*:*:*
EPSS
Процентиль: 83%
0.01855
Низкий
7.5 High
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-98
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
MobSF allows attackers to read arbitrary files via a crafted HTTP request
EPSS
Процентиль: 83%
0.01855
Низкий
7.5 High
CVSS3
Дефекты
NVD-CWE-noinfo
CWE-98