apache/cordova-plugin-inappbrowser

apache/cordova-plugin-inappbrowser

Releases78
Frequency1 month 4 weeks
Last Release
Stars1.14K
Apache Cordova InAppBrowser Plugin

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH

The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 through 2.9.0 does not properly validate callback identifiers, which allows remote attackers to execute arbitrary JavaScript in the host page and consequently gain privileges via a crafted gap-iab: URI.