Description
Insufficient validation in cross-origin communication (postMessage) in reveal.js version 3.9.1 and earlier allow attackers to perform cross-site scripting attacks.
Remediation
References
https://hackerone.com/reports/691977
Related Vulnerabilities
CVE-2021-29486 Vulnerability in npm package cumulative-distribution-function
CVE-2021-3163 Vulnerability in npm package quill
CVE-2022-31183 Vulnerability in maven package co.fs2:fs2-io_sjs1_3
CVE-2023-39410 Vulnerability in maven package org.apache.avro:avro
CVE-2022-31170 Vulnerability in npm package @openzeppelin/contracts-upgradeable