Skip to content
appaloosa scout logo main rounded
fr en
MEDIUM 5.3

CVE-2015-1835

Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xml, allows remote attackers to modify undefined secondary configuration variables (preferences) via a crafted intent: URL.

CVSS v3 CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N

Vulnerable CPE configurations

Vendor Product Platform Versions CPE 2.3 URI
apache cordova Android ≤3.7.1 cpe:2.3:a:apache:cordova:*:*:*:*:*:android:*:*
apache cordova Android cpe:2.3:a:apache:cordova:4.0.0:*:*:*:*:android:*:*
apache cordova Android cpe:2.3:a:apache:cordova:4.0.1:*:*:*:*:android:*:*
View on NVD ↗