Wildcard Detected in Scheme Portion of Content Security Policy (CSP) Directive Severity: Information Summary# Invicti detected that wildcard was used in scheme portion of a CSP directive. Impact# Wildcard cannot be used in schema. If you use wildcard in schema, it will be ignored by the browsers. Remediation# Remove the wildcard from schema. Classifications# ISO27001-A.14.2.5 Further Reading# Content Security Policy (CSP) Explained Invicti Security Insights Using Content Security Policy (CSP) to secure web applications Remote Hardware Takeover via Vulnerable Admin Software The dangers of incorrect CSP implementations Leverage Browser Security Features to Secure Your Website Vulnerability Index You can search and find all vulnerabilities Select Category Critical High Medium Low Best Practice Information OR Search Vulnerability Tags CSP Related Vulnerabilities Blind SQL Injection SQL Injection Local File Inclusion Misconfigured Access-Control-Allow-Origin Header Missing X-Frame-Options Header