CVE-2015-1835: Apache Cordova
Medium severity, CVSS 5.3. EPSS: 5.9% chance of exploitation in the next 30 days.
Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xml, allows remote attackers to modify undefined secondary configuration variables (preferences) via a crafted intent: URL.
Affected products
- Apache Cordova: up to and including 3.7.1; version 4.0.0 only; version 4.0.1 only
Published 2017-10-27. Last modified 2026-06-17.