Acunetix 360 detected that one of following CSP directives is used:
unsafe-eval
unsafe-inline
By using unsafe-eval , you allow the use of string evaluation functions like eval .
By using unsafe-inline , you allow the execution of inline scripts, which almost defeats the purpose of CSP. When this is allowed, it's very easy to successfully exploit a Cross-site Scripting vulnerability on your website.
Acunetix 360 detected that one of following CSP directives is used:
unsafe-inline
By using unsafe-eval , you allow the use of string evaluation functions like eval .
By using unsafe-inline , you allow the execution of inline scripts, which almost defeats the purpose of CSP. When this is allowed, it's very easy to successfully exploit a Cross-site Scripting vulnerability on your website.
Finding Id : [38248266|https://qa.armorcode.ai/#/findings/278/1413/38248266]