VDB
Sign up
HIGH8.3

GHSA-j5mf-6rh3-rhgg

CleverTap Web SDK is vulnerable to DOM-based XSS via handleCustomHtmlPreviewPostMessageEvent function

Quick fix

GHSA-j5mf-6rh3-rhgg — clevertap-web-sdk: upgrade to the fixed version with the command below.

npm install clevertap-web-sdk@1.15.3

Details

CleverTap Web SDK version 1.15.2 and earlier is vulnerable to Cross-site Scripting (XSS) via window.postMessage. The handleCustomHtmlPreviewPostMessageEvent function in src/util/campaignRender/nativeDisplay.js performs insufficient origin validation using the includes() method, which can be bypassed by an attacker using a subdomain.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/clevertap-web-sdk
Introduced in: 0Fixed in: 1.15.3
Fixnpm install clevertap-web-sdk@1.15.3

References