Weak Content Security Policy

Weak Content Security Policy

Description

A permissive CSP weakens defense against XSS. Broad script-source permissions, unsafe-inline, or unsafe-eval can increase opportunities to bypass it.

Potential impact

Injected scripts may enable session theft or disclosure of client-side data.

Remediation

Restrict default sources and allow scripts only from necessary origins. Use a nonce- or hash-based CSP where appropriate.

Examples

Before

php
<?php
header("Content-Security-Policy: script-src 'self' unpkg.com cdn.jsdelivr.net;");

After

php
<?php
header("Content-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none';");

Explanation:

  • Before: The policy permits scripts from shared hosting origins that may serve content controlled by other users.
  • After: The policy restricts sources to the same origin and blocks embedded objects. This example has no nonce or hash; review same-origin uploads and scripts as well. CSP does not replace output encoding.

References