CVE detail
CVE-2020-11990 — CVE-2020-11990
Published 2020-12-01 · Modified 2026-06-17 · Vendor apache · Product cordova · Source nvd
LOW
severity
CVSS-derived band
0.0073
EPSS probability
exploitation probability, 30d
51.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
We have resolved a security issue in the camera plugin that could have affected certain Cordova (Android) applications. An attacker who could install (or lead the victim to install) a specially crafted (or malicious) Android application would be able to access pictures taken with the app externally.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References