CVE-2018-4943

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
19/05/2018
Last modified:
28/06/2018

Description

Adobe PhoneGap Push Plugin versions 1.8.0 and earlier have an exploitable Same-Origin Method Execution vulnerability. Successful exploitation could lead to JavaScript code execution in the context of the PhoneGap app.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:adobe:push_notifications:*:*:*:*:*:phonegap:*:* 1.8.0 (including)