clevertap-web-sdk is vulnerable to Cross-site Scripting (XSS)
71
High Risk
Affected versions of this package are affected by security misconfiguration that allows Cross-Site Scripting (XSS) due to a missing restriction on iframe embedding. The affected object validation does not safely enforce the frame-ancestors secure directives, allowing external domains to load the popup within an iframe. If the popup processes user-controlled input without proper sanitization or encoding, an attacker can inject and execute JavaScript, resulting in session hijacking, clickjacking, or other client-side exploits.
You are affected if you are using a version that falls within the vulnerable range.
clevertap-web-sdk is vulnerable to Cross-site Scripting (XSS) in versions 1.0.0 - 1.12.1.
Upgrade the clevertap-web-sdk library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant