Severity: Information
Netsparker detected that object-src is missed in CSP declaration. It allows the injection of plugins which can execute JavaScript.
object-src
Set object-src to 'none' in CSP declaration:
'none'
Content-Security-Policy: object-src 'none';
Vulnerability Index
You can search and find all vulnerabilities
Select Category
Search Vulnerability
Tags
Related Vulnerabilities
Dead accurate, fast & easy-to-use Web Application Security Scanner