CWE-16
ISO27001-A.14.2.5
WASC-15
OWASP 2013-A5
OWASP 2017-A6

Content Security Policy (CSP) Keywords Not Used Within Single Quotes

Severity:
Information
Summary

Invicti detected that Content Security Policy (CSP) keywords like self, none, unsafe-inline, unsafe-eval were used within single quotes.

Impact

CSP keywords need to be used within single quotes according to CSP specifications, when not used the keywords will be considered as a part of the resource URL.

Remediation

Use these keywords within single quotes.

Required Skills for Successful Exploitation
Actions To Take
Vulnerability Index

You can search and find all vulnerabilities

Select Vulnerability
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.