What is CVE-2025-51684?
CVE-2025-51684: A Cross Site Scripting (XSS) vulnerability in CleverTap Web SDK v1.15.1. The flaw allows attackers to inject malicious scripts because the application fails to sanitize data received via `window.postMessage` before promoting it into the DOM via the `renderCustomHtml` function. Users should immediately update to the latest patched version.
Azərbaycanca: CVE-2025-51684: CleverTap Web SDK v1.15.1-də aşkarlanan Cross Site Scripting (XSS) zəifliyidir. Bu zəiflik, `window.postMessage` vasitəsilə alınan məlumatların `renderCustomHtml` funksiyası tərəfindən DOM-a yeridilmədən əvvəl sanitizə edilməməsi səbəbindən baş verir. Təcili olaraq SDK-ı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which specific CleverTap component is affected by CVE-2025-51684?
The `renderCustomHtml` function in CleverTap Web SDK version 1.15.1.
What action should be taken to mitigate this XSS vulnerability?
Immediately update the SDK to the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.