CVE-2023-2507
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
15/07/2023
Last modified:
24/09/2025
Description
CleverTap Cordova Plugin version 2.6.2 allows a remote attacker to execute JavaScript code in any application that is opened via a specially constructed deeplink by an attacker.<br />
<br />
This is possible because the plugin does not correctly validate the data coming from the deeplinks before using them.
Impact
Base Score 3.x
9.30
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:clevertap:clevertap:2.6.2:*:*:*:*:cordova:*:* |
To consult the complete list of CPE names with products and versions, see this page



