Vulnerabilities (CVE)

Filtered by vendor Apache Subscribe
Filtered by product Cordova Inappbrowser
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-0219 2 Apache, Oracle 3 Cordova Inappbrowser, Instantis Enterprisetrack, Retail Xstore Point Of Service 2024-11-21 7.5 HIGH 9.8 CRITICAL
A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI.