t4t5 / sweetalert

A beautiful replacement for JavaScript's "alert"
https://sweetalert.js.org
MIT License
22.4k stars 2.84k forks source link

Overly permissive message posting policy #916

Open kush100993 opened 4 years ago

kush100993 commented 4 years ago

Hi,

We are using sweetalert in our project. Recently we did a HP Fortify Scan and found a vulnerability in the sweetalert.min.js, the 'origin' for pushMessage() is '*' which flags as Overly Permissive Message Policy during the scan. Is there a fix for this.

This issue is flagged as Low Severity.

Thanks.