Description
Insufficient validation in cross-origin communication (postMessage) in reveal.js version 3.9.1 and earlier allow attackers to perform cross-site scripting attacks.
Remediation
References
https://hackerone.com/reports/691977
Related Vulnerabilities
CVE-2019-10795 Vulnerability in maven package org.webjars.npm:undefsafe
CVE-2022-36096 Vulnerability in maven package org.xwiki.platform:xwiki-platform-index-ui
CVE-2022-30506 Vulnerability in maven package net.mingsoft:ms-mcms
CVE-2023-39153 Vulnerability in maven package org.jenkins-ci.plugins:gitlab-oauth