CVE-2023-2507

All FrameworksApache CordovaCWE-79CVE-2023-2507

CVE-2023-2507

State: PUBLISHED · Published: 2023-07-15 · Updated: 2025-09-24 · Assigner: Fluid Attacks
Description
CleverTap Cordova Plugin version 2.6.2 allows a remote attacker to execute JavaScript code in any application that is opened via a specially constructed deeplink by an attacker. This is possible because the plugin does not correctly validate the data coming from the deeplinks before using them.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2023/2xxx/CVE-2023-2507.json