xss due to incorrect handling of postmessages