CVE-2015-1835

Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xml, allows remote attackers to modify undefined secondary configuration variables (preferences) via a crafted intent: URL.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:cordova:*:*:*:*:*:android:*:*
cpe:2.3:a:apache:cordova:4.0.0:*:*:*:*:android:*:*
cpe:2.3:a:apache:cordova:4.0.1:*:*:*:*:android:*:*

History

21 Nov 2024, 02:26

Type Values Removed Values Added
References () http://blog.trendmicro.com/trendlabs-security-intelligence/trend-micro-discovers-apache-vulnerability-that-allows-one-click-modification-of-android-apps/ - Exploit, Technical Description, Third Party Advisory () http://blog.trendmicro.com/trendlabs-security-intelligence/trend-micro-discovers-apache-vulnerability-that-allows-one-click-modification-of-android-apps/ - Exploit, Technical Description, Third Party Advisory
References () http://www.securityfocus.com/bid/74866 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/74866 - Third Party Advisory, VDB Entry
References () https://cordova.apache.org/announcements/2015/05/26/android-402.html - Release Notes, Vendor Advisory () https://cordova.apache.org/announcements/2015/05/26/android-402.html - Release Notes, Vendor Advisory

Information

Published : 2017-10-27 19:29

Updated : 2024-11-21 02:26


NVD link : CVE-2015-1835

Mitre link : CVE-2015-1835

CVE.ORG link : CVE-2015-1835


JSON object : View

Products Affected

apache

  • cordova
CWE
CWE-20

Improper Input Validation