Description
MobSF is a mobile application security testing tool used. In version 4.4.0, an authenticated user who uploaded a specially prepared one.a, can write arbitrary files to any directory writable by the user of the MobSF process. This issue has been patched in version 4.4.1.
Problem types
CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Product status
References
github.com/...-MobSF/security/advisories/GHSA-9gh8-9r95-3fc3
github.com/...ommit/7f3bc086c028c1b50889cab8a15f7b59b7abdaf9
github.com/...e-Security-Framework-MobSF/releases/tag/v4.4.1