Configuration Vulnerability in Apache Cordova for Android Applications
CVE-2015-1835
5.3MEDIUM
Summary
The vulnerability affects Apache Cordova for Android applications prior to versions 3.7.2 and 4.0.2. In instances where applications fail to define explicit values within the config.xml file, malicious actors can exploit undefined secondary configuration variables. This is achieved via specially crafted intent URLs, allowing potential alterations to application behavior without user consent. It is crucial for developers to ensure proper configuration to safeguard their applications from unauthorized modifications.
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved