Security Advisory

CVE-2015-5204

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2015-12-17 19:00:00
Last updated 2024-08-06 06:41:08
Assigner redhat
CVSS score not scored
State PUBLISHED

Description

CRLF injection vulnerability in the Apache Cordova File Transfer Plugin (cordova-plugin-file-transfer) for Android before 1.3.0 allows remote attackers to inject arbitrary headers via CRLF sequences in the filename of an uploaded file.