clevertap-web-sdk is vulnerable to Cross-site Scripting (XSS)
56
Medium Risk
Affected versions of this package are vulnerable to Cross-Site Scripting (XSS) in the Custom HTML Template feature due to insufficient validation of the message origin in postMessage communications. An attacker could exploit this flaw by hosting a malicious website that sends crafted JavaScript payloads via postMessage to the vulnerable application, which would then execute the script in the context of the target domain. Since the application did not verify the sender's origin, any website could send arbitrary scripts, potentially leading to session hijacking, data theft, or unauthorized actions on behalf of the user.
You are affected if you are using a version that falls within the vulnerable range.
clevertap-web-sdk is vulnerable to Cross-site Scripting (XSS) in versions 1.9.1 - 1.15.1.
Upgrade the clevertap-web-sdk library to the patch version
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant