Apache Cordova-Android before 4.1.0, when an application relies on a remote server, improperly implements a JavaScript whitelist protection mechanism, which allows attackers to bypass intended access restrictions via a crafted URI.
                
            References
                    Configurations
                    History
                    No history.
Information
                Published : 2015-11-23 11:59
Updated : 2018-10-09 19:57
NVD link : CVE-2015-5256
Mitre link : CVE-2015-5256
CVE.ORG link : CVE-2015-5256
JSON object : View
Products Affected
                apache
- cordova
 
CWE
                
                    
                        
                        CWE-264
                        
            Permissions, Privileges, and Access Controls
