Description
Insufficient validation in cross-origin communication (postMessage) in reveal.js version 3.9.1 and earlier allow attackers to perform cross-site scripting attacks.
Remediation
References
https://hackerone.com/reports/691977
Related Vulnerabilities
CVE-2019-16728 Vulnerability in npm package dompurify
CVE-2023-46499 Vulnerability in npm package @evershop/evershop
CVE-2021-23648 Vulnerability in npm package @braintree/sanitize-url
CVE-2022-23059 Vulnerability in maven package com.shopizer:sm-shop-model
CVE-2023-26136 Vulnerability in maven package org.webjars.bowergithub.salesforce:tough-cookie