jantinnerezo / livewire-alert

SweetAlert2 wrapper for Livewire
https://livewire-alert.jantinnerezo.com
MIT License
682 stars 73 forks source link

xss atack #117

Closed TimurTurdyev closed 7 months ago

TimurTurdyev commented 1 year ago

The documentation contains a link to the package //cdn.jsdelivr.net/npm/sweetalert2@11 which makes the injection https://github.com/sweetalert2/sweetalert2/blob/8854f295cf296026a4e090daf943895232342abd/src/SweetAlert.js#L261 and inserts the anthem of Ukraine for users from Russia

gally90 commented 10 months ago

The documentation contains a link to the package //cdn.jsdelivr.net/npm/sweetalert2@11 which makes the injection https://github.com/sweetalert2/sweetalert2/blob/8854f295cf296026a4e090daf943895232342abd/src/SweetAlert.js#L261 and inserts the anthem of Ukraine for users from Russia

Nice