# CVE-2024-52888 - Mobile Access File Share applications are vulnerable to stored XSS attacks

Please read this important update from Check Point.

Security Alert:

- **Severity:** Medium  
- **Product:** Mobile Access / SSL VPN  
- **Version:** R81.10 (EOS), R81.20, R82  
- **OS:** Gaia  
- **Last Modified:** 2025-04-27

## Symptoms

- When an authenticated Mobile Access portal end-user browses to a File Share application, the portal may run a script while attempting to display a directory or some file's properties. Additionally, an authenticated attacker may store specially crafted _file/dir_ names for other authenticated end-users to 'see'.

So far today, no attack with actual impact is known.

- This issue received the ID [CVE-2024-52888](https://www.cve.org/CVERecord?id=CVE-2024-52888)

## Solution

This problem was fixed. The fix is included in:

- [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 14
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 99
- [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 173

## Article Properties

- **Access Level:** General  
- **Severity:** Medium  
- **Status:** Approved  
- **Date Created:** 2025-01-21  
- **Last Modified:** 2025-04-27
