CleverTap Cordova Plugin version 2.6.2 allows a remote attacker to execute JavaScript code in any application that is opened via a specially constructed deeplink by an attacker.
This is possible because the plugin does not correctly validate the data coming from the deeplinks before using them.
This is possible because the plugin does not correctly validate the data coming from the deeplinks before using them.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-2174 | CleverTap Cordova plugin vulnerable to Cross-site Scripting |
Github GHSA |
GHSA-x2ph-qqwm-9cc6 | CleverTap Cordova plugin vulnerable to Cross-site Scripting |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 24 Sep 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CleverTap Cordova Plugin version 2.6.2 allows a remote attacker to execute JavaScript code in any application that is opened via a specially constructed deeplink by an attacker. This is possible because the plugin does not correctly validate the data coming from the deeplinks before using them. | CleverTap Cordova Plugin version 2.6.2 allows a remote attacker to execute JavaScript code in any application that is opened via a specially constructed deeplink by an attacker. This is possible because the plugin does not correctly validate the data coming from the deeplinks before using them. |
| References |
|
Wed, 30 Oct 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Fluid Attacks
Published:
Updated: 2025-09-24T14:10:13.526Z
Reserved: 2023-05-03T22:24:15.786Z
Link: CVE-2023-2507
Updated: 2024-08-02T06:26:08.920Z
Status : Modified
Published: 2023-07-15T19:15:09.527
Modified: 2025-09-24T14:15:46.170
Link: CVE-2023-2507
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA