clevertap-web-sdk is vulnerable to Permissive Cross-domain Policy with Untrusted Domains
20
Low Risk
Affected versions of this package are vulnerable to a security bypass due to improper origin validation in the handleMessageEvent function, which uses includes() for loose domain matching (e.g., allowing evil.clevertap.com if the trusted domain was clevertap.com). An attacker who compromises any subdomain can bypass origin validation and conduct malicious postMessage spoofing attempts, potentially leading to Cross-site Scripting (XSS) or click-jacking attacks.
You are affected if you are using a version that falls within the vulnerable range.
clevertap-web-sdk is vulnerable to Permissive Cross-domain Policy with Untrusted Domains in versions 1.14.2 - 1.15.2.
Upgrade the clevertap-web-sdk library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant