Cross-site Referrer Leakage through usage of unsafe-url in Referrer-Policy

Severity: Information
Summary#

Invicti detected that the Referrer-Policy permits Referrer leakage by using unsafe-url.

Impact#

If any traffic occurs from this site to a cross-site, the full URL will be leaked through the Referer header in the request.

Remediation#

See all available options by using links in External References and use a secure one.

Invicti

Dead accurate, fast & easy-to-use Web Application Security Scanner

Get a demo