Cross-site scripting in Inappbrowser - CVE-2019-0219
Published: January 20, 2020
Vulnerability details
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data passed via a specially crafted gap-iab: URI. A remote attacker can trick the victim to follow a specially crafted link and execute arbitrary JavaScript code in the main application's webview on the Android device.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.
Affected software
cordova-plugin-inappbrowser
Oracle Transportation Management
Oracle Retail Xstore Point of Service
Instantis EnterpriseTrack
How to mitigate CVE-2019-0219
cordova-plugin-inappbrowser - update to 3.1.0
External References
Related Security Bulletins
- Cross-site scripting in Apache Inappbrowser plugin for Cordova
- Privilege escalation in cordova-plugin-inappbrowser package for NPM
- Multiple vulnerabilities in Instantis EnterpriseTrack
- Multiple vulnerabilities in Oracle Retail Xstore Point of Service
- Cross-site scripting in Oracle Transportation Management