Custodela / dvna-shard-test

Damn Vulnerable NodeJS Application
MIT License
0 stars 0 forks source link

CX Missing_CSP_Header @ core/apphandler.js [master] #9

Closed tsunez closed 4 years ago

tsunez commented 4 years ago

Missing_CSP_Header issue exists @ core/apphandler.js in branch master

A Content Security Policy is not explicitly defined within the web-application.

Severity: Low

CWE:346

Vulnerability details and guidance

Checkmarx

Recommended Fix

Lines: 21


Code (Line #21):

            res.render('app/usersearch', {