Intel

AIKIDO-2025-10320

clevertap-web-sdk is vulnerable to Cross-site Scripting (XSS)

Cross-site Scripting (XSS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published May 23, 2025

56

Medium Risk

This Affects:

jsclevertap-web-sdk
1.9.1 - 1.15.1
Fixed in 1.15.2
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to Cross-Site Scripting (XSS) in the Custom HTML Template feature due to insufficient validation of the message origin in postMessage communications. An attacker could exploit this flaw by hosting a malicious website that sends crafted JavaScript payloads via postMessage to the vulnerable application, which would then execute the script in the context of the target domain. Since the application did not verify the sender's origin, any website could send arbitrary scripts, potentially leading to session hijacking, data theft, or unauthorized actions on behalf of the user.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

clevertap-web-sdk is vulnerable to Cross-site Scripting (XSS) in versions 1.9.1 - 1.15.1.

How to fix this

Upgrade the clevertap-web-sdk library to the patch version