Intel

AIKIDO-2025-10104

clevertap-web-sdk is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Feb 21, 2025

71

High Risk

This Affects:

JSclevertap-web-sdk
1.0.0 - 1.12.1
Fixed in 1.13.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are affected by security misconfiguration that allows Cross-Site Scripting (XSS) due to a missing restriction on iframe embedding. The affected object validation does not safely enforce the frame-ancestors secure directives, allowing external domains to load the popup within an iframe. If the popup processes user-controlled input without proper sanitization or encoding, an attacker can inject and execute JavaScript, resulting in session hijacking, clickjacking, or other client-side exploits.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

clevertap-web-sdk is vulnerable to Cross-site Scripting (XSS) in versions 1.0.0 - 1.12.1.

How to fix this

Upgrade the clevertap-web-sdk library to the patch version.