VYPR
Critical severityNVD Advisory· Published Jul 15, 2023· Updated Sep 24, 2025

CleverTap Cordova Plugin 2.6.2 - Reflected XSS

CVE-2023-2507

Description

CleverTap Cordova Plugin version 2.6.2 allows a remote attacker to execute JavaScript code in any application that is opened via a specially constructed deeplink by an attacker.

This is possible because the plugin does not correctly validate the data coming from the deeplinks before using them.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
clevertap-cordovanpm
< 2.7.02.7.0

Affected products

2

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.