Content Security Policy (CSP) Nonce Value Not Used Within Single Quotes

Severity: Information

Invicti detected that the nonce value declared in CSP is not within single quotes.


When nonce value is not used within single quotes, it will be considered as a part of the resource URL. This will cause relevant script block to not run.


Use nonce values within single quotes, i.e.

Content-Security-Policy: script-src 'nonce-EDNnf03nceIOfn39fn3e9h3sdfa';
Invicti Logo

Dead accurate, fast & easy-to-use Web Application Security Scanner

Get a demo