Security Advisory
CVE-2015-1835
CVE vulnerability detail - eXtreme Datacenter Security Operations
Description
Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xml, allows remote attackers to modify undefined secondary configuration variables (preferences) via a crafted intent: URL.