Complimentary 90-day, on-prem license available for entities involved in Covid19 response.
Summary

Netsparker detected that object-src is missed in CSP declaration. It allows the injection of plugins which can execute JavaScript.

Remediation

Set object-src to 'none' in CSP declaration:

Content-Security-Policy: object-src 'none';

Classifications
CWE-16, ISO27001-A.14.2.5, WASC-15, OWASP PC-C9
Vulnerability Index

Vulnerability Index

You can search and find all vulnerabilities

OR

Search Vulnerability

Tags

CSP 
Netsparker

Dead accurate, fast & easy-to-use Web Application Security Scanner

GET A DEMO