Description
Insufficient validation in cross-origin communication (postMessage) in reveal.js version 3.9.1 and earlier allow attackers to perform cross-site scripting attacks.
Remediation
References
Related Vulnerabilities
Envoy Proxy Integer Underflow (Wrap or Wraparound) Vulnerability (CVE-2024-32975)
WordPress Plugin Advance Search for WooCommerce Cross-Site Scripting (1.0.9)
Plone CMS Improper Privilege Management Vulnerability (CVE-2020-7941)
Internet Information Services Other Vulnerability (CVE-1999-0738)
WordPress Plugin All-in-One WP Migration Cross-Site Scripting (6.45)