CVE-2020-8127

Publication date

2020-02-28 19:25:46

Family

hackerone

State

PUBLISHED

Description

Insufficient validation in cross-origin communication (postMessage) in reveal.js version 3.9.1 and earlier allow attackers to perform cross-site scripting attacks.