An open-source component used to display PDF files on WikiLeaks.org contains vulnerabilities that could be exploited to launch cross-site scripting and content spoofing attacks against visitors. The vulnerability was first reported Thursday on the WikiLeaks supporters forum. The company has released FlexPaper 2.3.0 to address the vulnerabilities. WikiLeaks.com published the documents Sunday and directly linked to the PDF files instead of displaying them in an embedded viewer. The incident comes after Wired reported last week that in 2012 the FBI used a Flash-based component to decloak Tor users.”]

