Cross-site Referrer Leakage through usage of unsafe-url in Referrer-Policy

Severity: Information

Invicti detected that the Referrer-Policy permits Referrer leakage by using unsafe-url.


If any traffic occurs from this site to a cross-site, the full URL will be leaked through the Referer header in the request.


See all available options by using links in External References and use a secure one.

Invicti Logo

Dead accurate, fast & easy-to-use Web Application Security Scanner

Get a demo