VDB
Sign up
HIGH8.3

GHSA-jfrq-hj9f-c8qx

CleverTap Web SDK is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage

Quick fix

GHSA-jfrq-hj9f-c8qx — clevertap-web-sdk: upgrade to the fixed version with the command below.

npm install clevertap-web-sdk@1.15.3

Details

CleverTap Web SDK version 1.15.2 and earlier is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage in the Visual Builder module. The origin validation in src/modules/visualBuilder/pageBuilder.js (lines 56-60) uses the includes() method to verify the originUrl contains "dashboard.clevertap.com", which can be bypassed by an attacker using a crafted subdomain.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/clevertap-web-sdk
Introduced in: 0Fixed in: 1.15.3
Fixnpm install clevertap-web-sdk@1.15.3

References