Vulnerabilities/

Cross site scripting in reveal.js

Severity:
Medium

Description

The onmessage event listener in /plugin/notes/speaker-view.html does not check the origin of postMessage before adding the content to the webpage.

Recommendation

Update the reveal.js package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
reveal.js
Anything's wrong? Let us know Last updated on February 03, 2023

This issue is available in SmartScanner Professional

See Pricing