S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Oct 1, 2024

CVE-2024-41955 Scanner

CVE-2024-41955 scanner - Open Redirect vulnerability in MobSF

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.1k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-41955
5.2
CVSSmedium
Exploitable remotely over the internet · requires high privileges · user interaction needed.

Mobile Security Framework (MobSF) is a security research platform for mobile applications in Android, iOS and Windows Mobile. An open redirect vulnerability exist in MobSF authentication view. Update to MobSF v4.0.5.

Attack Vector
Network
Privileges Req.
High
User Interaction
Required
Affected
Mobile-Security-Framework-MobSFby MobSF
< 4.0.5
Updated Sep 10, 2026View on NVD →
Detail

Mobile Security Framework (MobSF) is a widely-used platform for mobile application security testing. It is developed for Android, iOS, and Windows Mobile applications. Researchers and security professionals utilize MobSF to identify vulnerabilities in mobile applications and enhance their security posture. The platform provides automated analysis tools that streamline the security assessment process. Users rely on MobSF to ensure their mobile applications are secure against emerging threats.

The open redirect vulnerability in MobSF allows attackers to manipulate the application's redirection process. This issue arises during the authentication phase of the application. An attacker can exploit this vulnerability to redirect users to harmful or malicious websites. Such exploitation can facilitate phishing attacks, leading to potential data breaches and unauthorized access.

The vulnerability is located in the login redirect feature of the MobSF application. When a user attempts to log in, the application processes the next parameter in the URL. If the parameter is manipulated, it can direct users to untrusted domains. For instance, an attacker could alter the login URL to redirect users to a malicious site after authentication. This could compromise the user's credentials or sensitive information.

If exploited, this vulnerability can lead to severe consequences, including phishing attacks. Attackers can deceive users into providing sensitive information, such as usernames and passwords. The malicious redirection can also distribute malware to unsuspecting users. Ultimately, it undermines the security of the application and the trust of its users.

Join the S4E platform today and gain access to advanced scanning capabilities that protect your digital assets. By using our services, you'll benefit from comprehensive security assessments that identify vulnerabilities before they can be exploited. Our platform provides actionable insights and remediation guidance tailored to your needs. Become a member to stay ahead of emerging threats and ensure the safety of your applications and data.

References:

Solution Advice
  • Implement strict validation of redirect URLs to ensure they point to trusted domains.
  • Use whitelisting for acceptable redirect URLs.
  • Educate users about the risks of clicking on suspicious links.
  • Regularly update MobSF and other applications to the latest versions to patch vulnerabilities.
  • Monitor user activities and logs for any suspicious redirection attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-41955 scanner - Open Redirect vulnerability in MobSF | S4E