Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5f44-2f3g-gf6q

Опубликовано: 14 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 through 2.9.0 does not properly validate callback identifiers, which allows remote attackers to execute arbitrary JavaScript in the host page and consequently gain privileges via a crafted gap-iab: URI.

The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 through 2.9.0 does not properly validate callback identifiers, which allows remote attackers to execute arbitrary JavaScript in the host page and consequently gain privileges via a crafted gap-iab: URI.

EPSS

Процентиль: 93%
0.11445
Средний

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
больше 8 лет назад

The CDVInAppBrowser class in the Apache Cordova In-App-Browser standalone plugin (org.apache.cordova.inappbrowser) before 0.3.2 for iOS and the In-App-Browser plugin for iOS from Cordova 2.6.0 through 2.9.0 does not properly validate callback identifiers, which allows remote attackers to execute arbitrary JavaScript in the host page and consequently gain privileges via a crafted gap-iab: URI.

CVSS3: 9.8
fstec
почти 12 лет назад

Уязвимость класса CDVInAppBrowser расширения Cordova In-App-Browser, позволяющая нарушителю повысить свои привилегии и выполнить произвольный JavaScript-код

EPSS

Процентиль: 93%
0.11445
Средний

9.8 Critical

CVSS3