Cross-site Referrer Leakage through usage of unsafe-url in Referrer-Policy

Severity: Information

Invicti detected that the Referrer-Policy permits Referrer leakage by using unsafe-url.


If any traffic occurs from this site to a cross-site, the full URL will be leaked through the Referer header in the request.


See all available options by using links in External References and use a secure one.

Build your resistance to threats. And save hundreds of hours each month.

Get a demo See how it works