Improper Whitelist Implementation in Apache Cordova-Android
CVE-2015-5256

Currently unrated

Key Information:

Vendor

Apache

Status
Vendor
CVE Published:
23 November 2015

What is CVE-2015-5256?

This vulnerability in Apache Cordova-Android versions prior to 4.1.0 arises from an inadequate implementation of the JavaScript whitelist protection mechanism. Attackers can exploit this flaw to bypass intended access restrictions when an application relies on connections to a remote server. By crafting a malicious URI, an attacker can gain unauthorized access, potentially leading to the execution of harmful scripts or fetching sensitive data from the vulnerable application.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2015-5256 : Improper Whitelist Implementation in Apache Cordova-Android