Content Security Policy (CSP) Nonce Without Matching Script Block Severity: Information Summary# Invicti detected that the page does not contain any script blocks with the nonce declared in CSP. Remediation# Ensure that all the script blocks has a matching nonce. If this nonce is not necessary then remove it from CSP. Classifications# WASC-15, ISO27001-A.14.2.5, OWASP 2017-A6, OWASP 2013-A5, CWE-16 Further Reading# Content Security Policy (CSP) Explained Invicti Security Insights Using Content Security Policy (CSP) to Secure Web Applications Remote Hardware Takeover via Vulnerable Admin Software The dangers of incorrect CSP implementations Leverage Browser Security Features to Secure Your Website Vulnerability Index You can search and find all vulnerabilities Select Category Critical High Medium Low Best Practice Information OR Search Vulnerability Tags CSP OWASP 2013-A5 OWASP 2017-A6 Related Vulnerabilities Web Cache Deception Server-Side Request Forgery (trace.axd) Code Execution via Local File Inclusion Code Execution via File Upload Text4Shell Remote Code Execution – (CVE-2022-42889)