Summary

Netsparker detected that object-src is missed in CSP declaration. It allows the injection of plugins which can execute JavaScript.

Remediation

Set object-src to 'none' in CSP declaration:

Content-Security-Policy: object-src 'none';

Classifications
OWASP PC-C9
Vulnerability Index

Vulnerability Index

You can search and find all vulnerabilities

Select Category

OR

Search Vulnerability

;
Netsparker

Dead accurate, fast & easy-to-use Web Application Security Scanner

GET A DEMO