Configuration Vulnerability in Apache Cordova for Android Applications
CVE-2015-1835
5.3MEDIUM
What is CVE-2015-1835?
The vulnerability affects Apache Cordova for Android applications prior to versions 3.7.2 and 4.0.2. In instances where applications fail to define explicit values within the config.xml file, malicious actors can exploit undefined secondary configuration variables. This is achieved via specially crafted intent URLs, allowing potential alterations to application behavior without user consent. It is crucial for developers to ensure proper configuration to safeguard their applications from unauthorized modifications.