CVE-2015-1835
Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xml
Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xml, allows remote attackers to modify undefined secondary configuration variables (preferences) via a crafted intent: URL.
MEDIUM · CVSS 5.3
EPSS 0.00625
Schedule remediation
- Public exploit or PoC is available
Sigma rules0
YARA rules0