PT-2026-66576 · Clevertap · Clevertap Web Sdk
CVE-2025-51684
·
Published
2026-07-30
·
Updated
2026-07-31
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CleverTap Web SDK version 1.15.1
Description
Cross Site Scripting (XSS) occurs because the application fails to sanitize untrusted data received via
window.postMessage before injecting it into the page DOM. An attacker can craft a malicious message that, when processed by the renderCustomHtml() function, leads to the execution of arbitrary JavaScript within the context of the hosting site.Recommendations
As a temporary workaround, restrict the use of the
renderCustomHtml() function until a patch is available.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Clevertap Web Sdk