CVE Database
/

CVE-2019-0219

Back to search

CVE-2019-0219

Published: Jan 14, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

A website running in the InAppBrowser webview on Android could execute arbitrary JavaScript in the main application's webview using a specially crafted gap-iab: URI.

VendorProductVersions

Apache

Cordova

affected
Cordova Android applications using the InAppBrowser plugin ( cordova-plugin-inappbrowser version 3.0.0 and below )

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now