Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 PyPI

MobSF allows attackers to read arbitrary files via a crafted HTTP request

GHSA-f42p-vc8p-7x54 · CVE-2022-41547

Published · Modified

Description

Mobile Security Framework (MobSF) v0.9.2 and below was discovered to contain a local file inclusion (LFI) vulnerability in the StaticAnalyzer/views.py script. This vulnerability allows attackers to read arbitrary files via a crafted HTTP request.

Ready to move

Start Securing

Free, no credit card | First findings in minutes