Description
A permissive CSP weakens defense against XSS. Broad script-source permissions, unsafe-inline, or unsafe-eval can increase opportunities to bypass it.
Potential impact
Injected scripts may enable session theft or disclosure of client-side data.
Remediation
Restrict default sources and allow scripts only from necessary origins. Use a nonce- or hash-based CSP where appropriate.
Examples
Before
php
<?php
header("Content-Security-Policy: script-src 'self' unpkg.com cdn.jsdelivr.net;");
After
php
<?php
header("Content-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none';");
Explanation:
- Before: The policy permits scripts from shared hosting origins that may serve content controlled by other users.
- After: The policy restricts sources to the same origin and blocks embedded objects. This example has no nonce or hash; review same-origin uploads and scripts as well. CSP does not replace output encoding.