Description
Insufficient validation in cross-origin communication (postMessage) in reveal.js version 3.9.1 and earlier allow attackers to perform cross-site scripting attacks.
Remediation
References
https://hackerone.com/reports/691977
Related Vulnerabilities
CVE-2021-23352 Vulnerability in npm package madge
CVE-2021-41193 Vulnerability in maven package com.wire:avs
CVE-2021-41042 Vulnerability in maven package org.eclipse.lyo:lyo-parent
CVE-2022-41935 Vulnerability in maven package org.xwiki.platform:xwiki-platform-livetable-ui
CVE-2019-0230 Vulnerability in maven package org.apache.struts:struts2-core