Missing object-src in CSP Declaration

Severity: Information
Summary#

Invicti detected that object-src is missed in CSP declaration. It allows the injection of plugins which can execute JavaScript.

Remediation#

Set object-src to 'none' in CSP declaration:

Content-Security-Policy: object-src 'none';

Classifications#
OR

Search Vulnerability

Tags

CSP

Build your resistance to threats. And save hundreds of hours each month.

Get a demo See how it works